enhancesoft
Security Risk Profile
28
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 48 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 3, 2005 to present
48
Total CVEs
14
Critical+High
0
Exploited
6
Unpatched
Threat Assessment
Avg CVSS
6.3
Base severity
Avg EPSS
9%
Exploit probability
Unpatched
6
Critical/High
Risk Level
28/100
low
Severity Distribution
Critical
3High
11Medium
33Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
1<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
30
2
SQL Injection
6
3
SSRF
1
4
Malicious File Upload
1
5
Integer Overflow
1
Most Affected Products
1. Enhancesoft osTicket93
2. osTicket osTicket56
3. Enhancesoft Audit Log Osticket2
Recent Vulnerabilities
See more →CVE-2026-9507
CVSS 5.1EPSS 0%medium
Session fixation vulnerability in Enhancesoft's osTicket
6/16/2026🔧 No Patch
CVE-2026-26895
CVSS 5.3medium
4/2/2026🔧 No Patch
CVE-2026-22200
CVSS 8.7EPSS 17%high
osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
1/12/2026🔧 No Patch
CVE-2025-26241
CVSS 6.5medium
5/5/2025🔧 No Patch
CVE-2023-46967
CVSS 6.1medium
2/20/2024
CVE-2023-27148
CVSS 4.8medium
10/23/2023🔧 No Patch
CVE-2023-27149
CVSS 4.8medium
10/23/2023🔧 No Patch
CVE-2021-45811
CVSS 6.5medium
9/8/2023🔧 No Patch
CVE-2023-30082
CVSS 7.5high
6/14/2023🔧 No Patch
CVE-2022-31888
CVSS 8.8high
4/5/2023
Monitor enhancesoft in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.