CVE-2026-44230
- EPSS 0.16%
- Veröffentlicht 20.07.2026 19:25:16
- Zuletzt bearbeitet 07.08.2026 13:27:19
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can...
CVE-2026-44231
- EPSS 0.25%
- Veröffentlicht 20.07.2026 19:20:43
- Zuletzt bearbeitet 07.08.2026 13:25:18
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-adminis...
CVE-2026-44229
- EPSS 0.14%
- Veröffentlicht 20.07.2026 19:18:25
- Zuletzt bearbeitet 18.08.2026 18:55:02
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an a...
CVE-2026-44228
- EPSS 0.15%
- Veröffentlicht 20.07.2026 17:34:28
- Zuletzt bearbeitet 07.08.2026 13:26:31
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An auth...
CVE-2026-44227
- EPSS 0.16%
- Veröffentlicht 20.07.2026 17:32:48
- Zuletzt bearbeitet 07.08.2026 13:25:56
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL...
CVE-2026-41076
- EPSS 0.39%
- Veröffentlicht 22.05.2026 21:36:21
- Zuletzt bearbeitet 23.07.2026 11:10:00
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under ce...
CVE-2026-41075
- EPSS 0.34%
- Veröffentlicht 22.05.2026 21:17:36
- Zuletzt bearbeitet 23.07.2026 11:10:00
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries wit...
CVE-2026-41074
- EPSS 0.12%
- Veröffentlicht 22.05.2026 21:12:41
- Zuletzt bearbeitet 23.07.2026 11:10:00
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger ...
CVE-2026-41073
- EPSS 0.17%
- Veröffentlicht 22.05.2026 21:10:22
- Zuletzt bearbeitet 23.07.2026 11:10:00
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before...
CVE-2025-30087
- EPSS 0.29%
- Veröffentlicht 28.05.2025 00:00:00
- Zuletzt bearbeitet 03.11.2025 20:18:09
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.