Bestpractical / RT
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44230 | RT: Reflected Cross-Site Scripting in search results chart | MEDIUM | 6.1 | Jul 20, 2026 |
| CVE-2026-44231 | RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint | CRITICAL | 9.1 | Jul 20, 2026 |
| CVE-2026-44229 | RT: Cross-Site Scripting via inline-served uploaded content | MEDIUM | 5.4 | Jul 20, 2026 |
| CVE-2026-44228 | RT: Stored Cross-Site Scripting via insufficient template escaping | MEDIUM | 5.4 | Jul 20, 2026 |
| CVE-2026-44227 | RT: Reflected Cross-Site Scripting via URL parameters | MEDIUM | 6.1 | Jul 20, 2026 |
| CVE-2026-41076 | RT: LDAP authentication bypass via empty password | HIGH | 8.1 | May 22, 2026 |
| CVE-2026-41075 | RT: SQL injection via entry_aggregator parameter in JSON search | HIGH | 8.8 | May 22, 2026 |
| CVE-2026-41074 | RT has broken CSRF protection for authenticated users | HIGH | 7.1 | May 22, 2026 |
| CVE-2026-41073 | RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and similar apps | MEDIUM | 4.6 | May 22, 2026 |
| CVE-2025-31501 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. | HIGH | 7.2 | May 28, 2025 |
| CVE-2025-31500 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. | HIGH | 7.2 | May 28, 2025 |
| CVE-2025-30087 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL. | HIGH | 7.2 | May 28, 2025 |
| CVE-2014-1474 | Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of servi… | MEDIUM | 5.0 | Jul 15, 2014 |
| CVE-2013-5587 | Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary… | LOW | 2.6 | Aug 23, 2013 |
| CVE-2013-3374 | Unspecified vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13, when using the Apache::Session::File session store, allows remot… | MEDIUM | 4.3 | Aug 23, 2013 |
| CVE-2013-3373 | CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and c… | MEDIUM | 5.0 | Aug 23, 2013 |
| CVE-2013-3372 | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly condu… | MEDIUM | 4.3 | Aug 23, 2013 |
| CVE-2013-3371 | Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web s… | MEDIUM | 4.3 | Aug 23, 2013 |
| CVE-2013-3370 | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remote attacker… | MEDIUM | 6.8 | Aug 23, 2013 |
| CVE-2013-3369 | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to exe… | MEDIUM | 6.0 | Aug 23, 2013 |
| CVE-2013-3368 | bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary… | LOW | 3.3 | Aug 23, 2013 |
| CVE-2012-4733 | Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticat… | MEDIUM | 6.0 | Aug 23, 2013 |
| CVE-2012-4884 | Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspe… | MEDIUM | 5.0 | Nov 11, 2012 |
| CVE-2012-4734 | Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protec… | MEDIUM | 5.0 | Nov 11, 2012 |
| CVE-2012-4732 | Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, all… | MEDIUM | 6.8 | Nov 11, 2012 |
Showing 1 to 25 of 45 CVEs