Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Znuny

First CVE: Apr 29, 2024Active for: 2 yearsTotal CVEs: 13
36.9
VTI Score
Medium

Znuny is a help-desk and IT service-management platform whose vulnerability profile centers on its single core product and skews toward critical-severity outcomes. The recurring exposure involves application-layer input-handling and authorization weaknesses—code injection, cross-site scripting, eval injection, SQL injection, and improper access control—that are characteristic of web-facing ticketing systems and reflect parser and query-building complexity in such platforms. Defenders should treat this vendor's advisories as a patching priority for internet-reachable instances; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Znuny over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 29, 2024
2 years ago
Most Recent CVE
Jun 5, 2026
50 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-26846CRITICAL
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.
May 12, 20259.830NONO
CVE-2026-50592MEDIUM
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).
Jun 5, 20266.428NONO
CVE-2025-26845CRITICAL
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the
May 8, 20259.828NONO
CVE-2025-26844CRITICAL
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
May 8, 20259.828NONO
CVE-2024-32491CRITICAL
An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an a
Apr 29, 20249.827NONO
CVE-2026-50591MEDIUM
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.
Jun 5, 20265.426NONO
CVE-2025-26847HIGH
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
May 8, 20257.522NONO
CVE-2025-26842HIGH
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the Communica
May 8, 20257.522NONO
CVE-2024-32493HIGH
An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX requ
Apr 29, 20248.822NONO
CVE-2024-48938HIGH
Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to
Oct 11, 20247.521NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
31%
38%
31%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Znuny.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Znuny — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Znuny's Products

View all 1 CNAs →

Top CWEs