Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

tickets — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in tickets, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses, vulnerabilities, and defects associated with the "tickets" product line, encompassing a wide range of vulnerability types from vendor advisories to general tags. It aggregates a comprehensive collection of reported issues, covering security flaws from the earliest recorded incidents up to the most recent disclosures available in the database. By consolidating this data, the page allows users to track a vendor's historical advisory patterns, understand the prevalence and characteristics of specific weakness classes within this software, and look up a detailed vulnerability history for the "tickets" product to assess its security posture over time. This resource serves as a centralized reference point for security researchers, developers, and risk analysts who need to evaluate past security incidents without navigating multiple disparate sources. The inclusion of varied vulnerability types ensures a holistic view of potential risks, enabling stakeholders to identify trends, prioritize remediation efforts based on historical data, and maintain an accurate understanding of the product's security landscape. This straightforward aggregation supports informed decision-making and enhances transparency regarding past security challenges faced by the product.

Vendor: SPIP

CVE ID Title CVSS Severity Published
CVE-2026-48219 Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter CWE-79 5.4 Medium 2026-05-21
CVE-2026-48218 Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id Parameters CWE-79 5.4 Medium 2026-05-21
CVE-2026-48217 Open ISES Tickets < 3.44.2 Reflected XSS via delete_module.php Multiple POST Parameters CWE-79 5.4 Medium 2026-05-21
CVE-2026-48216 Open ISES Tickets < 3.44.2 Reflected XSS via db_loader.php Multiple POST Parameters CWE-79 5.4 Medium 2026-05-21
CVE-2026-48215 Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter CWE-79 5.4 Medium 2026-05-21
CVE-2026-48214 Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter CWE-79 5.4 Medium 2026-05-21
CVE-2026-48213 Open ISES Tickets < 3.44.2 Reflected XSS via add.php ticket_id Parameter CWE-79 5.4 Medium 2026-05-21
CVE-2026-35016 Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35015 Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35014 Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35013 Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and thelng Parameters CWE-79 4.6 Medium 2026-05-20
CVE-2026-35012 Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35011 Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35010 Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35009 Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35008 Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-35007 Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter CWE-79 4.6 Medium 2026-05-20
CVE-2026-27744 SPIP tickets < 4.3.3 Unauthenticated RCE CWE-94 9.8 Critical 2026-02-25

All 48 known CVE vulnerabilities affecting tickets with full Chinese analysis, references, and POCs where available.