6.9

CVSS4.0

CVE-2026-34722 - Zammad is missing authorization in ticket create endpoint

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if the related parameter for adding links is used. This vulnerability is fixed in 7.0.1 and 6.5.4.

📅 Published: April 8, 2026, 6:13 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

5.9

CVSS4.0

CVE-2026-34721 - Zammad has Cross-site request forgery (CSRF) in OAuth callback endpoints

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4.

📅 Published: April 8, 2026, 6:12 p.m. 🔄 Last Modified: April 9, 2026, 2:22 p.m.

2.3

CVSS4.0

CVE-2026-34720 - Zammad has an origin validation error in SSO mechanism

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the header originates from a trusted SSO proxy/gateway before applying further actions on it. This vulnerability is fixed in 7.0.1 and 6.5.4.

📅 Published: April 8, 2026, 6:11 p.m. 🔄 Last Modified: April 9, 2026, 4:17 p.m.

8.3

CVSS4.0

CVE-2026-34719 - Zammad has a Server-side request forgery (SSRF) via webhooks

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could end up in retrieving co…

📅 Published: April 8, 2026, 6:02 p.m. 🔄 Last Modified: April 10, 2026, 8:38 p.m.

5.3

CVSS4.0

CVE-2026-34718 - Zammad improperly neutralizes of script-related HTML tags in ticket articles

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The Zammad GUI is render…

📅 Published: April 8, 2026, 6:01 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

2.1

CVSS4.0

CVE-2026-34248 - Zammad has an information disclosure in ticket detail view of customers in shared organizations

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority, custom ticket attribu…

📅 Published: April 8, 2026, 6 p.m. 🔄 Last Modified: April 9, 2026, 4:17 p.m.

7.5

CVSS3.1

CVE-2026-34392 - LORIS has a path traversal in static router

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory…

📅 Published: April 8, 2026, 5:57 p.m. 🔄 Last Modified: April 9, 2026, 2:23 p.m.

8.5

CVSS4.0

CVE-2026-30818 - OS Command Injection Vulnerability in dnsmasq Module in TP-Link AX53

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker t…

📅 Published: April 8, 2026, 5:54 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.8

CVSS4.0

CVE-2026-30817 - Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, pot…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.8

CVSS4.0

CVE-2026-30816 - Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, p…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.
Total resulsts: 343919
Page 64 of 34,392
« previous page » next page
Filters