Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OTRS AG — Vulnerabilities & Security Advisories 81

Browse all 81 CVE security advisories affecting OTRS AG. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OTRS AG develops open-source IT service management software, primarily functioning as a ticketing system for enterprise support and incident tracking. The platform’s extensive feature set and long market presence have resulted in a significant historical vulnerability footprint, with 73 Common Vulnerabilities and Exposures currently recorded. Analysis of these flaws reveals a pattern of critical security weaknesses, most notably Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which often stem from insufficient input validation in legacy modules. Additionally, several instances of privilege escalation have been documented, allowing unauthorized users to gain administrative control. While the vendor has implemented regular patching cycles to address these issues, the high volume of past exploits highlights the complexity of securing a mature, feature-rich application. Organizations deploying this solution must prioritize rigorous patch management and strict access controls to mitigate the residual risks associated with its extensive attack surface.

Found 54 results / 81 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-48187 Email with special content can lead to DoS — OTRS CWE-400 5.7 Medium 2026-06-01
CVE-2026-48188 SQL Injection via MySQL Quote Method — OTRS CWE-20 9.1 Critical 2026-06-01
CVE-2026-48189 Bypass DedicatedAgentToCustomerGroups Setting — OTRS CWE-200 5.7 Medium 2026-06-01
CVE-2026-48190 Incorrect handling of permissions in External Interface Config Item List module — OTRS CWE-276 3.5 Low 2026-06-01
CVE-2026-48191 Wrong Permission Handling in Document Search Article Meta Filters — OTRS CWE-276 3.5 Low 2026-06-01
CVE-2026-48208 Denial-of-Service via SVG Rendering in Ticket — OTRS CWE-400 6.5 Medium 2026-06-01
CVE-2026-48209 Reflected XSS in authenticated agent context — OTRS CWE-79 7.1 High 2026-06-01
CVE-2026-48210 Possible information disclosure via External Interface — OTRS CWE-200 5.7 Medium 2026-05-31
CVE-2026-6060 Possible DoS via SQL Box — OTRS CWE-400 4.5 Medium 2026-04-20
CVE-2025-24391 Possible user enumeration — OTRS CWE-203 5.3 Medium 2025-07-14
CVE-2025-24388 Unsafe handling of AJAX calls — OTRS CWE-184 3.8 Low 2025-06-16
CVE-2025-24387 Missing CSRF protection — OTRS CWE-1275 4.8 Medium 2025-03-10
CVE-2025-24390 Missing Cookie Flags — OTRS CWE-614 6.8 Medium 2025-01-27
CVE-2025-24389 SMTP Password will be shown in cleartext on some SMTP errors — OTRS CWE-532 6.3 Medium 2025-01-27
CVE-2024-43446 Improper check of permissions in Generic Interface — OTRS CWE-269 3.5 Low 2025-01-27
CVE-2024-43445 Missing X-Content-Type-Options: nosniff Header Allows MIME Type Sniffing — OTRS CWE-20 5.4 Medium 2025-01-27
CVE-2024-43444 Passwords are written to Admin Log Module — OTRS CWE-532 8.2 High 2024-08-26
CVE-2024-43443 Stored XSS in process management — OTRS CWE-790 4.9 Medium 2024-08-26
CVE-2024-43442 Stored XSS in System Configuration — OTRS CWE-790 4.9 Medium 2024-08-26
CVE-2024-23794 Agents are able to lock the ticket without the "Owner" permission — OTRS CWE-266 5.2 Medium 2024-07-15
CVE-2024-6540 Information exlosure in external interface — OTRS CWE-790 5.7 Medium 2024-07-15
CVE-2024-23793 Upload of files outside application directory — OTRS CWE-22 6.3 Medium 2024-06-06
CVE-2024-23790 Missing file type check in avatar picture upload — OTRS CWE-20 3.5 Low 2024-01-29
CVE-2024-23791 Unnecessary data is written to log if issues during indexing occurs — OTRS CWE-532 4.9 Medium 2024-01-29
CVE-2024-23792 Insufficient access control — OTRS CWE-287 5.3 Medium 2024-01-29
CVE-2023-6254 Password is send back to client — OTRS CWE-522 8.1 High 2023-11-27
CVE-2023-5421 Possible XSS execution in customer information — OTRS CWE-20 3.5 Low 2023-10-16
CVE-2023-38059 External pictures can be loaded even if not allowed by configuration — OTRS CWE-200 5.3 Medium 2023-10-16
CVE-2023-5422 SSL Certificates are not checked for E-Mail Handling — OTRS CWE-295 8.7 High 2023-10-16
CVE-2023-38060 Host header injection by attachments in web service — OTRS CWE-20 6.3 Medium 2023-07-24

This page lists every published CVE security advisory associated with OTRS AG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.