Zammad

Zammad

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 25.09.2026 16:48:34
  • Zuletzt bearbeitet 28.09.2026 14:45:39

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles through the article listing API. However, the same customer can directly request an attachment be...

  • EPSS 0.27%
  • Veröffentlicht 25.09.2026 16:46:50
  • Zuletzt bearbeitet 28.09.2026 14:45:39

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked items was not ...

  • EPSS 0.25%
  • Veröffentlicht 04.08.2026 18:12:04
  • Zuletzt bearbeitet 28.08.2026 15:31:31

Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.

  • EPSS 0.18%
  • Veröffentlicht 08.04.2026 18:20:00
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the ...

  • EPSS 0.17%
  • Veröffentlicht 08.04.2026 18:18:32
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/ai_assistance/text_tools/:id was not checking if a user is privileged to use the text tool, resulting in being able to use it...

  • EPSS 0.26%
  • Veröffentlicht 08.04.2026 18:17:30
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence t...

  • EPSS 0.44%
  • Veröffentlicht 08.04.2026 18:14:08
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system set...

  • EPSS 0.17%
  • Veröffentlicht 08.04.2026 18:13:20
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if the related parameter for adding links is used. This vulnerability is fixed in 7.0.1 and ...

  • EPSS 0.1%
  • Veröffentlicht 08.04.2026 18:12:32
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in...

  • EPSS 0.1%
  • Veröffentlicht 08.04.2026 18:11:23
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the header originates from a trusted SSO proxy/gateway before applying further actions on it. This vulnerabili...