All 4 CVE vulnerabilities found in osTicket, with AI-generated Chinese analysis, references, and POCs.
Vendor: Enhancesoft
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-14871 | osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure CWE-863 | - | - | 2026-07-17 |
| CVE-2026-9507 | Session fixation vulnerability in Enhancesoft's osTicket CWE-38 | - | - | 2026-06-16 |
| CVE-2026-8194 | osTicket Dispatcher class.dispatcher.php cross-site request forgery CWE-352 | 4.3 | Medium | 2026-05-09 |
| CVE-2026-22200 | osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read CWE-74 | 6.5AI | MediumAI | 2026-01-12 |
All 4 known CVE vulnerabilities affecting osTicket with full Chinese analysis, references, and POCs where available.