Zammad是德国Zammad公司的一套票务管理软件。 Zammad 7.0.1之前版本和6.5.4之前版本存在安全漏洞,该漏洞源于HTML清理器对data: URI方案清理不当,可能导致存储恶意内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34722 | Zammad is missing authorization in ticket create endpoint | |
| CVE-2026-34724 | Zammad has a server-side template injection leading to RCE via AI Agent | |
| CVE-2026-34837 | Zammad is miissing authorization in AI assistance controller for context data used in text | |
| CVE-2026-34248 | Zammad has an information disclosure in ticket detail view of customers in shared organiza | |
| CVE-2026-34720 | Zammad has an origin validation error in SSO mechanism | |
| CVE-2026-34721 | Zammad has Cross-site request forgery (CSRF) in OAuth callback endpoints | |
| CVE-2026-34719 | Zammad has a Server-side request forgery (SSRF) via webhooks | |
| CVE-2026-34782 | Zammad has improper access control in AI assistance controller for text tools | |
| CVE-2026-34723 | Zammad has incorrect access control in getting_started_controller |
No comments yet