Known vulnerabilities in osTicket 1.9.6
Vendor:
osTicket.com
Software:
osTicket
Version:
1.9.6
Software CPE:
cpe:2.3:a:osticket_com:osticket:*:*:*:*:*:*:*:*
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
5.3
Vulnerabilities by Severity
1.18.4
1.17.8
1.18.3
1.17.7
-
1.18.2
1.17.6
1.18.1
1.17.5
1.18
1.17.4
1.17.3
1.16.6
1.17
1.16.4
1.17.1
1.16.5
1.17.2
1.16.3
1.15.8
1.16.2
1.15.7
1.16.1
1.15.6
1.16
1.15.5
1.15.4
1.14.8
1.14.7
1.15.3
1.15.3.1
1.14.6
1.15.2
1.14.5
1.15.1
1.14.4
1.15
1.14.3
1.14.2
1.14.1
1.14
1.12.6
1.12.5
1.12.4
1.12.3
1.12.2
1.12.1
1.12
1.11
1.10.7
1.10.6
1.10.5
1.10.4
1.10.3
1.10.2
1.10.1
1.10
1.9.16
1.9.15
1.9.14
1.9.13
1.9.12
1.9.11
1.9.9
1.9.8.1
1.9.8
1.9.7
1.9.6
1.9.5.1
1.9.3
1.9.2
1.8.12
1.8.11
1.8.10
1.8.9
1.8.8
1.8.7
1.8.6
1.8.5
1.9.5
1.9.4
1.8.1
1.9.0
1.9.1
1.8.0
1.6.0
1.8.0.4
1.8.0.3
1.8.1.2
1.0
1.8.0.2
1.8.1.1
1.8.0.1
1.8.3
1.8.4
1.6
1
1.x
1.2.7
1.3.0
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU55412 - Improper Control of Interaction Frequency |
CWE-799 | Low | 1.14.7, 1.15.3 | 28.07.2021 |
SB2021072816 |
||
| #VU55411 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 1.14.7, 1.15.3 | 28.07.2021 |
SB2021072816 |
||
| #VU55410 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 1.14.7, 1.15.3 | 28.07.2021 |
SB2021072816 |
||
| #VU27509 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-12629 |
CWE-79 | Low | 1.14.2 | 04.05.2020 |
SB2020050427 |
||
| #VU31088 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-11537 |
CWE-79 | Low | 1.12 | 25.04.2019 |
SB2019042509 |