CVE-2026-44230
- EPSS 0.16%
- Veröffentlicht 20.07.2026 19:25:16
- Zuletzt bearbeitet 07.08.2026 13:27:19
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can...
CVE-2026-44231
- EPSS 0.25%
- Veröffentlicht 20.07.2026 19:20:43
- Zuletzt bearbeitet 07.08.2026 13:25:18
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-adminis...
CVE-2026-44229
- EPSS 0.14%
- Veröffentlicht 20.07.2026 19:18:25
- Zuletzt bearbeitet 18.08.2026 18:55:02
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an a...
CVE-2026-44228
- EPSS 0.15%
- Veröffentlicht 20.07.2026 17:34:28
- Zuletzt bearbeitet 07.08.2026 13:26:31
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An auth...
CVE-2026-44227
- EPSS 0.16%
- Veröffentlicht 20.07.2026 17:32:48
- Zuletzt bearbeitet 07.08.2026 13:25:56
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL...
CVE-2026-6841
- EPSS 0.24%
- Veröffentlicht 21.05.2026 11:49:07
- Zuletzt bearbeitet 23.07.2026 16:10:00
Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vu...
CVE-2025-61873
- EPSS 0.2%
- Veröffentlicht 16.01.2026 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
CVE-2025-9158
- EPSS 0.41%
- Veröffentlicht 24.10.2025 06:15:35
- Zuletzt bearbeitet 08.10.2026 11:10:00
The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enab...
CVE-2025-31501
- EPSS 0.22%
- Veröffentlicht 28.05.2025 00:00:00
- Zuletzt bearbeitet 09.06.2025 18:59:03
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
CVE-2025-31500
- EPSS 0.22%
- Veröffentlicht 28.05.2025 00:00:00
- Zuletzt bearbeitet 09.06.2025 18:58:52
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.