Security Advisories

Subscribe to the OTRS newsletter to stay up-to-date about releases and security updates.

Release name Release date Title References Risk level
OTRS Security Advisory 2019-01 01/18/2019 Stored XSS CVE-2019-9752 LOW
OTRS Security Advisory 2019-02 03/01/2019 XSS CVE-2019-9751 LOW
OTRS Security Advisory 2019-03 03/08/2019 Information Disclosure CVE-2019-9753 LOW
OTRS Security Advisory 2019-04 04/26/2019 XXE Processing CVE-2019-9892 MEDIUM
OTRS Security Advisory 2019-05 04/26/2019 Reflected and Stored XSS CVE-2019-10067 LOW
OTRS Security Advisory 2019-06 04/26/2019 Stored XSS CVE-2019-10066 LOW
OTRS Security Advisory 2019-07 04/26/2019 Information Disclosure CVE-2019-10065 LOW
OTRS Security Advisory 2019-08 05/31/2019 Loading External Image Resources CVE-2019-12248 LOW
OTRS Security Advisory 2019-09 05/31/2019 Information Disclosure CVE-2019-12497 LOW
OTRS Security Advisory 2019-10 07/12/2019 Information Disclosure CVE-2019-12746 LOW
OTRS Security Advisory 2019-11 07/12/2019 Information Disclosure CVE-2019-13457 LOW
OTRS Security Advisory 2019-12 07/12/2019 Information Disclosure CVE-2019-13458 LOW
OTRS Security Advisory 2019-13 10/04/2019 Stored XSS CVE-2019-16375 LOW
OTRS Security Advisory 2019-14 11/15/2019 Information Disclosure CVE-2019-18179 LOW
OTRS Security Advisory 2019-15 11/15/2019 Denial of service CVE-2019-18180 MEDIUM
OTRS Security Advisory 2020-01 01/10/2020 Spoofing of From field in several screens CVE-2020-1765 LOW
OTRS Security Advisory 2020-02 01/10/2020 Improper handling of uploaded inline images CVE-2020-1766 LOW
OTRS Security Advisory 2020-03 01/10/2020 Possible to send drafted messages as wrong agent CVE-2020-1767 LOW
OTRS Security Advisory 2020-04 02/07/2020 External interface does not invalidate user session CVE-2020-1768 MEDIUM
OTRS Security Advisory 2020-05 02/07/2020 Vulnerability in third-party library - jquery CVE-2019-11358 MEDIUM
OTRS Security Advisory 2020-06 03/27/2020 Autocomplete in the form login screens CVE-2020-1769 LOW
OTRS Security Advisory 2020-07 03/27/2020 Information disclosure in support bundle files CVE-2020-1770 LOW
OTRS Security Advisory 2020-08 03/27/2020 Possible XSS in Customer user address book CVE-2020-1771 MEDIUM
OTRS Security Advisory 2020-09 03/27/2020 Information Disclosure CVE-2020-1772 MEDIUM
OTRS Security Advisory 2020-10 03/27/2020 Session / Password token leak CVE-2020-1773 HIGH
OTRS Security Advisory 2020-11 04/27/2020 Information disclosure CVE-2020-1774 MEDIUM
OTRS Security Advisory 2020-12 06/08/2020 Information disclosure CVE-2020-1775 LOW
OTRS Security Advisory 2020-13 07/20/2020 Invalidating or changing user does not invalidate session CVE-2020-1776 LOW
OTRS Security Advisory 2020-14 10/12/2020 Vulnerability in third-party library - jquery CVE-2020-11023, CVE-2020-11022 MEDIUM
OTRS Security Advisory 2020-15 10/12/2020 Agent names disclosed in chat feature. CVE-2020-1777 MEDIUM
OTRS Security Advisory 2020-16 11/23/2020 Bypassing user account validation CVE-2020-1778 MEDIUM
Attention! Maximum security risk with OTRS 4 and OTRS 5! 12/23/2020 HIGH
Attention! Security risk with OTRS 6! 12/23/2020 HIGH
OTRS Security Advisory 2021-01 02/08/2021 XSS CVE-2021-21434 LOW
OTRS Security Advisory 2021-02 02/08/2021 Information exposure in PDF export CVE-2021-21435 MEDIUM
OTRS Security Advisory 2021-03 02/08/2021 Dynamic templates reveal sensitive data when OTRS tags are used CVE-2020-1779 MEDIUM
OTRS Security Advisory 2021-04 02/08/2021 Agent is able to link customer's Config Items without permission CVE-2021-21436 LOW
OTRS Security Advisory 2021-05 02/08/2021 Several Vulnerabilites in CKEditor CVE-2018-17960 MEDIUM
OTRS Security Advisory 2021-06 03/22/2021 ReDoS vulnerability in thirdparty library (jquery-validate) CVE-2021-21252 MEDIUM
OTRS Security Advisory 2021-07 03/22/2021 Config Items are shown to users without permission CVE-2021-21437 LOW
OTRS Security Advisory 2021-08 03/22/2021 FAQ articles are shown to users without permission CVE-2021-21438 LOW
OTRS Security Advisory 2021-09 06/14/2021 Possible DoS attack using a special crafted URL in email body CVE-2021-21439 MEDIUM
OTRS Security Advisory 2021-11 06/16/2021 XSS in the ticket overview screens CVE-2021-21441 HIGH
OTRS Security Advisory 2021-10 07/26/2021 Support Bundle includes S/Mime and PGP keys and secrets CVE-2021-21440, CVE-2021-36096 MEDIUM
OTRS Security Advisory 2021-12 07/26/2021 Accounting CVE-2021-21442 MEDIUM
OTRS Security Advisory 2021-13 07/26/2021 Unautorized listing of the customer user emails CVE-2021-21443 LOW
OTRS Security Advisory 2021-14 07/26/2021 Unautorized access to the calendar appointments CVE-2021-36091 LOW
OTRS Security Advisory 2021-15 07/26/2021 XSS attack using special link in email CVE-2021-36092 MEDIUM
OTRS Security Advisory 2021-16 09/06/2021 DoS attack using PostMaster filters CVE-2021-36093 MEDIUM
OTRS Security Advisory 2021-17 09/06/2021 XSS attack in appointment edit popup screen CVE-2021-36094 MEDIUM
OTRS Security Advisory 2021-18 09/06/2021 User enumeration issue using "lost password" feature CVE-2021-36095 MEDIUM
OTRS Security Advisory 2021-19 10/18/2021 Regular Expression Denial of Service in postcs CVE-2021-23368 MEDIUM
OTRS Security Advisory 2021-20 10/18/2021 Agents are able to lock the ticket without the "Owner" permission CVE-2021-36097 LOW
OTRS Security Advisory 2022-01 02/07/2022 Dynamic field error message is vulnerable to XSS CVE-2022-0473 LOW
OTRS Security Advisory 2022-02 02/07/2022 Disclosure of mail addresses CVE-2022-0474 LOW
OTRS Security Advisory 2022-04 02/07/2022 Several vulnerabilities in third-party npm modules CVE-2021-3803 / CVE-2021-3807 / CVE-2021-23368 MEDIUM
OTRS Security Advisory 2022-03 03/21/2022 Authenticated remote code execution CVE-2021-36100 MEDIUM
OTRS Security Advisory 2022-05 03/21/2022 Possible XSS attack via translation CVE-2022-0475 LOW
OTRS Security Advisory 2022-06 03/21/2022 Information disclosure in the External Interface CVE-2022-1004 MEDIUM
OTRS Security Advisory 2022-07 06/13/2022 OTRS version number is always in the exported ICS files CVE-2022-32739 LOW
OTRS Security Advisory 2022-08 06/13/2022 Information disclosure in the External Interface CVE-2022-32740 LOW
OTRS Security Advisory 2022-09 06/13/2022 Information disclosure in Request New Password feature CVE-2022-32741 MEDIUM
OTRS Security Advisory 2022-10 09/05/2022 Possible XSS in Admin Interface CVE-2022-39049 LOW
OTRS Security Advisory 2022-11 09/05/2022 Possible XSS stored in customer information CVE-2022-39050 MEDIUM
OTRS Security Advisory 2022-12 09/05/2022 Perl Code execution in Template Toolkit CVE-2022-39051 MEDIUM
OTRS Security Advisory 2022-13 10/17/2022 DoS attack using email CVE-2022-39052 HIGH
OTRS Security Advisory 2022-14 10/17/2022 Information exposure of template content due to missing check of permissions CVE-2022-3501 LOW
OTRS Security Advisory 2022-15 12/19/2022 Improper Input Validation vulnerability in OTRS and ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice CVE-2022-4427 MEDIUM
OTRS Security Advisory 2023-01 03/20/2023 Possible XSS in Ticket Actions CVE-2023-1248 MEDIUM
OTRS Security Advisory 2023-02 03/20/2023 Code execution through ACL creation CVE-2023-1250 HIGH
OTRS Security Advisory 2023-03 05/08/2023 Information disclouse and DoS via websocket push events CVE-2023-2534 HIGH
OTRS Security Advisory 2023-04 07/24/2023 Host header injection by attachments in web service CVE-2023-38060 MEDIUM
OTRS Security Advisory 2023-05 07/24/2023 Code execution via System Configuration CVE-2023-38056 HIGH
OTRS Security Advisory 2023-06 07/24/2023 Possible XSS stored in survey answers CVE-2023-38057 MEDIUM
OTRS Security Advisory 2023-07 07/24/2023 Tickets can be moved without permission CVE-2023-38058 MEDIUM
OTRS Security Advisory 2023-08 10/16/2023 External pictures can be loaded even if not allowed by configuration CVE-2023-38059 MEDIUM
OTRS Security Advisory 2023-09 10/16/2023 Possible XSS execution in customer information CVE-2023-5421 LOW
OTRS Security Advisory 2023-10 10/16/2023 SSL Certificates are not checked for E-Mail Handling CVE-2023-5422 HIGH
OTRS Security Advisory 2023-11 11/27/2023 Password is sent back to client CVE-2023-6254 HIGH
OTRS Security Advisory 2024-01 01/29/2024 Missing file type check in avatar picture upload CVE-2024-23790 LOW
OTRS Security Advisory 2024-02 01/29/2024 Unnecessary data is written to log if issues during indexing occurs CVE-2024-23791 MEDIUM
OTRS Security Advisory 2024-03 01/29/2024 Insufficient access control CVE-2024-23792 MEDIUM
OTRS Security Advisory 2024-04 01/29/2024 A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor CVE-2021-33829 MEDIUM
OTRS Security Advisory 2024-05 06/03/2024 Upload of files outside application directory CVE-2024-23793 MEDIUM
OTRS Security Advisory 2024-06 07/15/2024 Agents are able to lock the ticket without the "Owner" permission CVE-2024-23794 MEDIUM
OTRS Security Advisory 2024-07 07/15/2024 Information disclosure in external interface CVE-2024-6540 MEDIUM
OTRS Security Advisory 2024-08 07/15/2024 OpenSSH: Remote Code Execution CVE-2024-6387 HIGH
OTRS Security Advisory 2024-09 07/15/2024 IKEv1 default AH/ESP responder can crash and restart CVE-2024-3652 MEDIUM
OTRS Security Advisory 2024-10 08/26/2024 Stored XSS in System Configuration CVE-2024-43442 MEDIUM
OTRS Security Advisory 2024-11 08/26/2024 Stored XSS in process management CVE-2024-43443 MEDIUM
OTRS Security Advisory 2024-12 08/26/2024 Passwords are written to Admin Log Module CVE-2024-43444 HIGH
OTRS Security Advisory 2025-01 01/27/2025 Missing X-Content-Type-Options: nosniff Header Allows MIME Type Sniffing CVE-2024-43445 MEDIUM
OTRS Security Advisory 2025-02 01/27/2025 Improper check of permissions in Generic Interface CVE-2024-43446 LOW
OTRS Security Advisory 2025-03 01/27/2025 SMTP Password will be shown in cleartext on some SMTP errors CVE-2025-24389 MEDIUM
OTRS Security Advisory 2025-04 01/27/2025 Missing Cookie Flags CVE-2025-24390 MEDIUM
OTRS Security Advisory 2025-05 03/10/2025 Missing CSRF protection CVE-2025-24387 MEDIUM
OTRS Security Advisory 2025-06 06/16/2025 Unsafe handling of AJAX calls CVE-2025-24388 LOW
OTRS Security Advisory 2025-07 07/14/2025 Possible user enumeration CVE-2025-24391 MEDIUM
OTRS Security Advisory 2026-01 04/20/2026 Possible DoS via SQL Box CVE-2026-6060 Reduced
OTRS Security Advisory 2026-02 06/01/2026 SQL Injection via MySQL Quote Method CVE-2026-48188 Moderate
OTRS Security Advisory 2026-03 06/01/2026 Bypass DedicatedAgentToCustomerGroups Setting CVE-2026-48189 Reduced
OTRS Security Advisory 2026-04 06/01/2026 Incorrect handling of permissions in External Interface Config Item List module CVE-2026-48190 Reduced
OTRS Security Advisory 2026-05 06/01/2026 Wrong Permission Handing in Document Search Article Meta Filters CVE-2026-48191 Informational
OTRS Security Advisory 2026-06 06/01/2026 Email with special content can lead to DoS CVE-2026-48187 Moderate
OTRS Security Advisory 2026-07 06/01/2026 Denial-of-Service via SVG Rendering in Ticket CVE-2026-48208 Moderate
OTRS Security Advisory 2026-08 06/01/2026 Reflected XSS in authenticated agent context CVE-2026-48209 Reduced
OTRS Security Advisory 2026-09 06/01/2026 Possible information disclosure via External Interface CVE-2026-48210 Moderate
Release name Release date Title References Risk level