Security Advisories
Subscribe to the OTRS newsletter to stay up-to-date about releases and security updates.
| Release name | Release date | Title | References | Risk level |
|---|---|---|---|---|
| OTRS Security Advisory 2019-01 | 01/18/2019 | Stored XSS | CVE-2019-9752 | LOW |
| OTRS Security Advisory 2019-02 | 03/01/2019 | XSS | CVE-2019-9751 | LOW |
| OTRS Security Advisory 2019-03 | 03/08/2019 | Information Disclosure | CVE-2019-9753 | LOW |
| OTRS Security Advisory 2019-04 | 04/26/2019 | XXE Processing | CVE-2019-9892 | MEDIUM |
| OTRS Security Advisory 2019-05 | 04/26/2019 | Reflected and Stored XSS | CVE-2019-10067 | LOW |
| OTRS Security Advisory 2019-06 | 04/26/2019 | Stored XSS | CVE-2019-10066 | LOW |
| OTRS Security Advisory 2019-07 | 04/26/2019 | Information Disclosure | CVE-2019-10065 | LOW |
| OTRS Security Advisory 2019-08 | 05/31/2019 | Loading External Image Resources | CVE-2019-12248 | LOW |
| OTRS Security Advisory 2019-09 | 05/31/2019 | Information Disclosure | CVE-2019-12497 | LOW |
| OTRS Security Advisory 2019-10 | 07/12/2019 | Information Disclosure | CVE-2019-12746 | LOW |
| OTRS Security Advisory 2019-11 | 07/12/2019 | Information Disclosure | CVE-2019-13457 | LOW |
| OTRS Security Advisory 2019-12 | 07/12/2019 | Information Disclosure | CVE-2019-13458 | LOW |
| OTRS Security Advisory 2019-13 | 10/04/2019 | Stored XSS | CVE-2019-16375 | LOW |
| OTRS Security Advisory 2019-14 | 11/15/2019 | Information Disclosure | CVE-2019-18179 | LOW |
| OTRS Security Advisory 2019-15 | 11/15/2019 | Denial of service | CVE-2019-18180 | MEDIUM |
| OTRS Security Advisory 2020-01 | 01/10/2020 | Spoofing of From field in several screens | CVE-2020-1765 | LOW |
| OTRS Security Advisory 2020-02 | 01/10/2020 | Improper handling of uploaded inline images | CVE-2020-1766 | LOW |
| OTRS Security Advisory 2020-03 | 01/10/2020 | Possible to send drafted messages as wrong agent | CVE-2020-1767 | LOW |
| OTRS Security Advisory 2020-04 | 02/07/2020 | External interface does not invalidate user session | CVE-2020-1768 | MEDIUM |
| OTRS Security Advisory 2020-05 | 02/07/2020 | Vulnerability in third-party library - jquery | CVE-2019-11358 | MEDIUM |
| OTRS Security Advisory 2020-06 | 03/27/2020 | Autocomplete in the form login screens | CVE-2020-1769 | LOW |
| OTRS Security Advisory 2020-07 | 03/27/2020 | Information disclosure in support bundle files | CVE-2020-1770 | LOW |
| OTRS Security Advisory 2020-08 | 03/27/2020 | Possible XSS in Customer user address book | CVE-2020-1771 | MEDIUM |
| OTRS Security Advisory 2020-09 | 03/27/2020 | Information Disclosure | CVE-2020-1772 | MEDIUM |
| OTRS Security Advisory 2020-10 | 03/27/2020 | Session / Password token leak | CVE-2020-1773 | HIGH |
| OTRS Security Advisory 2020-11 | 04/27/2020 | Information disclosure | CVE-2020-1774 | MEDIUM |
| OTRS Security Advisory 2020-12 | 06/08/2020 | Information disclosure | CVE-2020-1775 | LOW |
| OTRS Security Advisory 2020-13 | 07/20/2020 | Invalidating or changing user does not invalidate session | CVE-2020-1776 | LOW |
| OTRS Security Advisory 2020-14 | 10/12/2020 | Vulnerability in third-party library - jquery | CVE-2020-11023, CVE-2020-11022 | MEDIUM |
| OTRS Security Advisory 2020-15 | 10/12/2020 | Agent names disclosed in chat feature. | CVE-2020-1777 | MEDIUM |
| OTRS Security Advisory 2020-16 | 11/23/2020 | Bypassing user account validation | CVE-2020-1778 | MEDIUM |
| Attention! Maximum security risk with OTRS 4 and OTRS 5! | 12/23/2020 | HIGH | ||
| Attention! Security risk with OTRS 6! | 12/23/2020 | HIGH | ||
| OTRS Security Advisory 2021-01 | 02/08/2021 | XSS | CVE-2021-21434 | LOW |
| OTRS Security Advisory 2021-02 | 02/08/2021 | Information exposure in PDF export | CVE-2021-21435 | MEDIUM |
| OTRS Security Advisory 2021-03 | 02/08/2021 | Dynamic templates reveal sensitive data when OTRS tags are used | CVE-2020-1779 | MEDIUM |
| OTRS Security Advisory 2021-04 | 02/08/2021 | Agent is able to link customer's Config Items without permission | CVE-2021-21436 | LOW |
| OTRS Security Advisory 2021-05 | 02/08/2021 | Several Vulnerabilites in CKEditor | CVE-2018-17960 | MEDIUM |
| OTRS Security Advisory 2021-06 | 03/22/2021 | ReDoS vulnerability in thirdparty library (jquery-validate) | CVE-2021-21252 | MEDIUM |
| OTRS Security Advisory 2021-07 | 03/22/2021 | Config Items are shown to users without permission | CVE-2021-21437 | LOW |
| OTRS Security Advisory 2021-08 | 03/22/2021 | FAQ articles are shown to users without permission | CVE-2021-21438 | LOW |
| OTRS Security Advisory 2021-09 | 06/14/2021 | Possible DoS attack using a special crafted URL in email body | CVE-2021-21439 | MEDIUM |
| OTRS Security Advisory 2021-11 | 06/16/2021 | XSS in the ticket overview screens | CVE-2021-21441 | HIGH |
| OTRS Security Advisory 2021-10 | 07/26/2021 | Support Bundle includes S/Mime and PGP keys and secrets | CVE-2021-21440, CVE-2021-36096 | MEDIUM |
| OTRS Security Advisory 2021-12 | 07/26/2021 | Accounting | CVE-2021-21442 | MEDIUM |
| OTRS Security Advisory 2021-13 | 07/26/2021 | Unautorized listing of the customer user emails | CVE-2021-21443 | LOW |
| OTRS Security Advisory 2021-14 | 07/26/2021 | Unautorized access to the calendar appointments | CVE-2021-36091 | LOW |
| OTRS Security Advisory 2021-15 | 07/26/2021 | XSS attack using special link in email | CVE-2021-36092 | MEDIUM |
| OTRS Security Advisory 2021-16 | 09/06/2021 | DoS attack using PostMaster filters | CVE-2021-36093 | MEDIUM |
| OTRS Security Advisory 2021-17 | 09/06/2021 | XSS attack in appointment edit popup screen | CVE-2021-36094 | MEDIUM |
| OTRS Security Advisory 2021-18 | 09/06/2021 | User enumeration issue using "lost password" feature | CVE-2021-36095 | MEDIUM |
| OTRS Security Advisory 2021-19 | 10/18/2021 | Regular Expression Denial of Service in postcs | CVE-2021-23368 | MEDIUM |
| OTRS Security Advisory 2021-20 | 10/18/2021 | Agents are able to lock the ticket without the "Owner" permission | CVE-2021-36097 | LOW |
| OTRS Security Advisory 2022-01 | 02/07/2022 | Dynamic field error message is vulnerable to XSS | CVE-2022-0473 | LOW |
| OTRS Security Advisory 2022-02 | 02/07/2022 | Disclosure of mail addresses | CVE-2022-0474 | LOW |
| OTRS Security Advisory 2022-04 | 02/07/2022 | Several vulnerabilities in third-party npm modules | CVE-2021-3803 / CVE-2021-3807 / CVE-2021-23368 | MEDIUM |
| OTRS Security Advisory 2022-03 | 03/21/2022 | Authenticated remote code execution | CVE-2021-36100 | MEDIUM |
| OTRS Security Advisory 2022-05 | 03/21/2022 | Possible XSS attack via translation | CVE-2022-0475 | LOW |
| OTRS Security Advisory 2022-06 | 03/21/2022 | Information disclosure in the External Interface | CVE-2022-1004 | MEDIUM |
| OTRS Security Advisory 2022-07 | 06/13/2022 | OTRS version number is always in the exported ICS files | CVE-2022-32739 | LOW |
| OTRS Security Advisory 2022-08 | 06/13/2022 | Information disclosure in the External Interface | CVE-2022-32740 | LOW |
| OTRS Security Advisory 2022-09 | 06/13/2022 | Information disclosure in Request New Password feature | CVE-2022-32741 | MEDIUM |
| OTRS Security Advisory 2022-10 | 09/05/2022 | Possible XSS in Admin Interface | CVE-2022-39049 | LOW |
| OTRS Security Advisory 2022-11 | 09/05/2022 | Possible XSS stored in customer information | CVE-2022-39050 | MEDIUM |
| OTRS Security Advisory 2022-12 | 09/05/2022 | Perl Code execution in Template Toolkit | CVE-2022-39051 | MEDIUM |
| OTRS Security Advisory 2022-13 | 10/17/2022 | DoS attack using email | CVE-2022-39052 | HIGH |
| OTRS Security Advisory 2022-14 | 10/17/2022 | Information exposure of template content due to missing check of permissions | CVE-2022-3501 | LOW |
| OTRS Security Advisory 2022-15 | 12/19/2022 | Improper Input Validation vulnerability in OTRS and ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice | CVE-2022-4427 | MEDIUM |
| OTRS Security Advisory 2023-01 | 03/20/2023 | Possible XSS in Ticket Actions | CVE-2023-1248 | MEDIUM |
| OTRS Security Advisory 2023-02 | 03/20/2023 | Code execution through ACL creation | CVE-2023-1250 | HIGH |
| OTRS Security Advisory 2023-03 | 05/08/2023 | Information disclouse and DoS via websocket push events | CVE-2023-2534 | HIGH |
| OTRS Security Advisory 2023-04 | 07/24/2023 | Host header injection by attachments in web service | CVE-2023-38060 | MEDIUM |
| OTRS Security Advisory 2023-05 | 07/24/2023 | Code execution via System Configuration | CVE-2023-38056 | HIGH |
| OTRS Security Advisory 2023-06 | 07/24/2023 | Possible XSS stored in survey answers | CVE-2023-38057 | MEDIUM |
| OTRS Security Advisory 2023-07 | 07/24/2023 | Tickets can be moved without permission | CVE-2023-38058 | MEDIUM |
| OTRS Security Advisory 2023-08 | 10/16/2023 | External pictures can be loaded even if not allowed by configuration | CVE-2023-38059 | MEDIUM |
| OTRS Security Advisory 2023-09 | 10/16/2023 | Possible XSS execution in customer information | CVE-2023-5421 | LOW |
| OTRS Security Advisory 2023-10 | 10/16/2023 | SSL Certificates are not checked for E-Mail Handling | CVE-2023-5422 | HIGH |
| OTRS Security Advisory 2023-11 | 11/27/2023 | Password is sent back to client | CVE-2023-6254 | HIGH |
| OTRS Security Advisory 2024-01 | 01/29/2024 | Missing file type check in avatar picture upload | CVE-2024-23790 | LOW |
| OTRS Security Advisory 2024-02 | 01/29/2024 | Unnecessary data is written to log if issues during indexing occurs | CVE-2024-23791 | MEDIUM |
| OTRS Security Advisory 2024-03 | 01/29/2024 | Insufficient access control | CVE-2024-23792 | MEDIUM |
| OTRS Security Advisory 2024-04 | 01/29/2024 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor | CVE-2021-33829 | MEDIUM |
| OTRS Security Advisory 2024-05 | 06/03/2024 | Upload of files outside application directory | CVE-2024-23793 | MEDIUM |
| OTRS Security Advisory 2024-06 | 07/15/2024 | Agents are able to lock the ticket without the "Owner" permission | CVE-2024-23794 | MEDIUM |
| OTRS Security Advisory 2024-07 | 07/15/2024 | Information disclosure in external interface | CVE-2024-6540 | MEDIUM |
| OTRS Security Advisory 2024-08 | 07/15/2024 | OpenSSH: Remote Code Execution | CVE-2024-6387 | HIGH |
| OTRS Security Advisory 2024-09 | 07/15/2024 | IKEv1 default AH/ESP responder can crash and restart | CVE-2024-3652 | MEDIUM |
| OTRS Security Advisory 2024-10 | 08/26/2024 | Stored XSS in System Configuration | CVE-2024-43442 | MEDIUM |
| OTRS Security Advisory 2024-11 | 08/26/2024 | Stored XSS in process management | CVE-2024-43443 | MEDIUM |
| OTRS Security Advisory 2024-12 | 08/26/2024 | Passwords are written to Admin Log Module | CVE-2024-43444 | HIGH |
| OTRS Security Advisory 2025-01 | 01/27/2025 | Missing X-Content-Type-Options: nosniff Header Allows MIME Type Sniffing | CVE-2024-43445 | MEDIUM |
| OTRS Security Advisory 2025-02 | 01/27/2025 | Improper check of permissions in Generic Interface | CVE-2024-43446 | LOW |
| OTRS Security Advisory 2025-03 | 01/27/2025 | SMTP Password will be shown in cleartext on some SMTP errors | CVE-2025-24389 | MEDIUM |
| OTRS Security Advisory 2025-04 | 01/27/2025 | Missing Cookie Flags | CVE-2025-24390 | MEDIUM |
| OTRS Security Advisory 2025-05 | 03/10/2025 | Missing CSRF protection | CVE-2025-24387 | MEDIUM |
| OTRS Security Advisory 2025-06 | 06/16/2025 | Unsafe handling of AJAX calls | CVE-2025-24388 | LOW |
| OTRS Security Advisory 2025-07 | 07/14/2025 | Possible user enumeration | CVE-2025-24391 | MEDIUM |
| OTRS Security Advisory 2026-01 | 04/20/2026 | Possible DoS via SQL Box | CVE-2026-6060 | Reduced |
| OTRS Security Advisory 2026-02 | 06/01/2026 | SQL Injection via MySQL Quote Method | CVE-2026-48188 | Moderate |
| OTRS Security Advisory 2026-03 | 06/01/2026 | Bypass DedicatedAgentToCustomerGroups Setting | CVE-2026-48189 | Reduced |
| OTRS Security Advisory 2026-04 | 06/01/2026 | Incorrect handling of permissions in External Interface Config Item List module | CVE-2026-48190 | Reduced |
| OTRS Security Advisory 2026-05 | 06/01/2026 | Wrong Permission Handing in Document Search Article Meta Filters | CVE-2026-48191 | Informational |
| OTRS Security Advisory 2026-06 | 06/01/2026 | Email with special content can lead to DoS | CVE-2026-48187 | Moderate |
| OTRS Security Advisory 2026-07 | 06/01/2026 | Denial-of-Service via SVG Rendering in Ticket | CVE-2026-48208 | Moderate |
| OTRS Security Advisory 2026-08 | 06/01/2026 | Reflected XSS in authenticated agent context | CVE-2026-48209 | Reduced |
| OTRS Security Advisory 2026-09 | 06/01/2026 | Possible information disclosure via External Interface | CVE-2026-48210 | Moderate |
| Release name | Release date | Title | References | Risk level |