Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zammad — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Zammad, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive overview of security vulnerabilities associated with Zammad, a popular open-source customer support ticketing system. It aggregates data from various sources to present a unified view of weaknesses affecting this specific software product, allowing stakeholders to assess risk and compliance effectively. The content covers a wide range of vulnerability types, including remote code execution, cross-site scripting, and authentication bypasses, spanning from the initial release of Zammad up to the most recently disclosed issues. This temporal scope ensures that users can review historical trends as well as current threats impacting the platform. By consulting this aggregation, you can efficiently track vendor security advisories and stay informed about patches and mitigation strategies released by the Zammad team. Furthermore, it serves as a reference for understanding how specific weakness classes manifest within the Zammad architecture, helping security professionals evaluate potential attack vectors. Users can also look up the product’s vulnerability history to identify recurring patterns or critical flaws that have been addressed in previous updates. This centralized resource eliminates the need to search multiple databases manually, providing a streamlined approach to managing security information. Whether you are a system administrator responsible for maintaining Zammad deployments or a security analyst conducting risk assessments, this page offers the necessary context to make informed decisions. The information is presented in a structured format to facilitate quick scanning and deep dives into individual entries, ensuring that both high-level overviews and detailed technical insights are readily accessible without requiring external links or complex navigation.

Vendor: Zammad GmbH

CVE IDTitleCVSSSeverityPublished
CVE-2026-34837 Zammad is miissing authorization in AI assistance controller for context data used in text tools CWE-862 7.1AIHighAI2026-04-08
CVE-2026-34782 Zammad has improper access control in AI assistance controller for text tools CWE-862 8.8AIHighAI2026-04-08
CVE-2026-34724 Zammad has a server-side template injection leading to RCE via AI Agent CWE-94 7.2AIHighAI2026-04-08
CVE-2026-34723 Zammad has incorrect access control in getting_started_controller CWE-284 7.5AIHighAI2026-04-08
CVE-2026-34722 Zammad is missing authorization in ticket create endpoint CWE-862 4.3AIMediumAI2026-04-08
CVE-2026-34721 Zammad has Cross-site request forgery (CSRF) in OAuth callback endpoints CWE-352 8.8AIHighAI2026-04-08
CVE-2026-34720 Zammad has an origin validation error in SSO mechanism CWE-346 7.1AIHighAI2026-04-08
CVE-2026-34719 Zammad has a Server-side request forgery (SSRF) via webhooks CWE-918 6.5AIMediumAI2026-04-08
CVE-2026-34718 Zammad improperly neutralizes of script-related HTML tags in ticket articles CWE-80 5.4AIMediumAI2026-04-08
CVE-2026-34248 Zammad has an information disclosure in ticket detail view of customers in shared organizations CWE-284 3.5AILowAI2026-04-08
CVE-2025-32358 Zammad 安全漏洞 CWE-918 4.0 Medium2025-04-05
CVE-2025-32359 Zammad 安全漏洞 CWE-602 4.8 Medium2025-04-05
CVE-2025-32360 Zammad 安全漏洞 CWE-402 4.2 Medium2025-04-05
CVE-2025-32357 Zammad 安全漏洞 CWE-288 4.3 Medium2025-04-05
CVE-2019-1010018 Zammad 跨站脚本漏洞 CWE-80 6.1 -2019-07-16

All 15 known CVE vulnerabilities affecting Zammad with full Chinese analysis, references, and POCs where available.