Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Tickets — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in Tickets, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the tickets product category, focusing on software weaknesses and security tags. It collects information on a wide variety of vulnerabilities, including remote code execution, cross-site scripting, and authentication bypasses, covering incidents reported from 2020 through the current quarter. By consolidating this information, the page allows security professionals and developers to efficiently track vendor advisories as they are released. Users can gain a deeper understanding of specific weakness classes by analyzing patterns in reported defects and exploit methods. Additionally, the historical data provides a comprehensive view of a product's vulnerability history, highlighting recurring issues and areas of persistent risk. This centralized resource simplifies the process of assessing the security posture of applications that manage ticketing systems. Instead of searching through disparate sources, readers can view trends in reported bugs and the corresponding mitigation strategies applied by vendors over time. The data supports informed decision-making for risk management and patch deployment. By presenting structured records of past and present vulnerabilities, this tool aids in predicting potential future attack vectors based on historical precedence. It serves as a reference for auditing existing implementations and ensuring that known security gaps are addressed. This aggregation is designed for technical audiences who require detailed, factual information without unnecessary commentary or promotional content. The goal is to provide a clear, accessible record of security incidents related to these products.

Vendor: SPIP

CVE IDTitleCVSSSeverityPublished
CVE-2026-48219 Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter CWE-79 5.4 Medium2026-05-21
CVE-2026-48218 Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id Parameters CWE-79 5.4 Medium2026-05-21
CVE-2026-48217 Open ISES Tickets < 3.44.2 Reflected XSS via delete_module.php Multiple POST Parameters CWE-79 5.4 Medium2026-05-21
CVE-2026-48216 Open ISES Tickets < 3.44.2 Reflected XSS via db_loader.php Multiple POST Parameters CWE-79 5.4 Medium2026-05-21
CVE-2026-48215 Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter CWE-79 5.4 Medium2026-05-21
CVE-2026-48214 Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter CWE-79 5.4 Medium2026-05-21
CVE-2026-48213 Open ISES Tickets < 3.44.2 Reflected XSS via add.php ticket_id Parameter CWE-79 5.4 Medium2026-05-21
CVE-2026-35016 Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35015 Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35014 Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35013 Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and thelng Parameters CWE-79 4.6 Medium2026-05-20
CVE-2026-35012 Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35011 Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35010 Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35009 Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35008 Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-35007 Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter CWE-79 4.6 Medium2026-05-20
CVE-2026-27744 SPIP tickets < 4.3.3 Unauthenticated RCE CWE-94 9.8 Critical2026-02-25

All 48 known CVE vulnerabilities affecting Tickets with full Chinese analysis, references, and POCs where available.