Exposure of osTicket
Issue trackers16
exposure score
347
sites use
0
exploited
1
critical
CVEs
6 resultsCVE-2026-22200HIGHosTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File ReadEPSS 73.1%CVE-2026-9507MEDIUMSession fixation vulnerability in Enhancesoft's osTicketEPSS 0.4%CVE-2026-36214MEDIUMosTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip cEPSS 0.3%CVE-2026-14871HIGHosTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosureEPSS 0.3%CVE-2026-18363CRITICALWeak password recovery mechanism in osTicket by Enhancesoft LLCEPSS 0.3%CVE-2026-8194MEDIUMosTicket Dispatcher class.dispatcher.php cross-site request forgeryEPSS 0.2%