Request Tracker
Bestpractical · 35 CVEs
RT: Reflected Cross-Site Scripting in search results chart
Jul 20, 2026
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
Jul 20, 2026
RT: Cross-Site Scripting via inline-served uploaded content
Jul 20, 2026
RT: Stored Cross-Site Scripting via insufficient template escaping
Jul 20, 2026
RT: Reflected Cross-Site Scripting via URL parameters
Jul 20, 2026
Reflected XSS in Request Tracker
May 21, 2026
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expo…
Jan 16, 2026
Stored XSS in Request Tracker
Oct 24, 2025
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
May 28, 2025
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
May 28, 2025
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramet…
May 28, 2025
Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME
May 5, 2025
Information exposure vulnerability in Request Tracker (RT)
Apr 4, 2024
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transa…
Nov 3, 2023
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-…
Nov 3, 2023
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed…
Nov 3, 2023
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
Jul 14, 2022
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an atta…
Jul 14, 2022
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive informat…
Oct 18, 2021
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote att…
Mar 17, 2019
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4…
Jul 3, 2017
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain s…
Jul 3, 2017
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time compar…
Jul 3, 2017
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x befo…
Jul 3, 2017
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows rem…
Sep 3, 2015
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-44230 | RT: Reflected Cross-Site Scripting in search results chart | MEDIUM | 0.26% | Jul 20, 2026 |
| CVE-2026-44231 | RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint | CRITICAL | 0.41% | Jul 20, 2026 |
| CVE-2026-44229 | RT: Cross-Site Scripting via inline-served uploaded content | MEDIUM | 0.24% | Jul 20, 2026 |
| CVE-2026-44228 | RT: Stored Cross-Site Scripting via insufficient template escaping | MEDIUM | 0.26% | Jul 20, 2026 |
| CVE-2026-44227 | RT: Reflected Cross-Site Scripting via URL parameters | MEDIUM | 0.26% | Jul 20, 2026 |
| CVE-2026-6841 | Reflected XSS in Request Tracker | MEDIUM | 0.40% | May 21, 2026 |
| CVE-2025-61873 | Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used. | LOW | 0.22% | Jan 16, 2026 |
| CVE-2025-9158 | Stored XSS in Request Tracker | MEDIUM | 0.45% | Oct 24, 2025 |
| CVE-2025-31501 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. | HIGH | 0.24% | May 28, 2025 |
| CVE-2025-31500 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. | HIGH | 0.24% | May 28, 2025 |
| CVE-2025-30087 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL. | HIGH | 0.31% | May 28, 2025 |
| CVE-2025-2545 | Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME | LOW | 0.19% | May 5, 2025 |
| CVE-2024-3262 | Information exposure vulnerability in Request Tracker (RT) | MEDIUM | 0.29% | Apr 4, 2024 |
| CVE-2023-45024 | Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder. | HIGH | 0.60% | Nov 3, 2023 |
| CVE-2023-41260 | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls. | HIGH | 0.70% | Nov 3, 2023 |
| CVE-2023-41259 | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or… | HIGH | 0.72% | Nov 3, 2023 |
| CVE-2022-25803 | Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search. | MEDIUM | 0.57% | Jul 14, 2022 |
| CVE-2022-25802 | Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment. | MEDIUM | 0.83% | Jul 14, 2022 |
| CVE-2021-38562 | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack again… | HIGH | 1.84% | Oct 18, 2021 |
| CVE-2018-18898 | The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity att… | HIGH | 2.36% | Mar 17, 2019 |
| CVE-2017-5944 | The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated us… | HIGH | 2.78% | Jul 3, 2017 |
| CVE-2017-5943 | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site re… | HIGH | 0.83% | Jul 3, 2017 |
| CVE-2017-5361 | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes… | MEDIUM | 1.37% | Jul 3, 2017 |
| CVE-2016-6127 | Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachm… | MEDIUM | 1.20% | Jul 3, 2017 |
| CVE-2015-6506 | Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web sc… | MEDIUM | 2.08% | Sep 3, 2015 |
Showing 1 to 25 of 35 CVEs