Search CVE reports


Toggle filters

1 – 10 of 74 results


CVE-2026-41076

Medium priority
Needs evaluation

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user...

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41075

Medium priority
Needs evaluation

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into...

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41074

Medium priority
Needs evaluation

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious...

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41073

Medium priority
Needs evaluation

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is...

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-6841

Medium priority
Needs evaluation

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the...

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44231

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44229

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44227

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28343

Medium priority
Needs evaluation

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor3 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61873

Medium priority
Needs evaluation

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

2 affected packages

request-tracker4, request-tracker5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker5 Needs evaluation Needs evaluation Needs evaluation
Show less packages