Where
-Infinity
0

Vendor Risk Score

See how zammad compares to other vendors in security performance

View Risk Score →

Zammad ZammadZammad 7.0.1 - Improper authorization in ticket article attachment cloning

Risk 40
Severity
7.1
First published (updated )

Zammad ZammadZammad is miissing authorization in AI assistance controller for context data used in text tools

Risk 26
Severity
5.3
First published (updated )

Zammad ZammadZammad has improper access control in AI assistance controller for text tools

Risk 26
Severity
5.3
First published (updated )

Zammad ZammadZammad has a server-side template injection leading to RCE via AI Agent

Risk 63
Severity
8.7
First published (updated )

Zammad ZammadZammad has incorrect access control in getting_started_controller

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zammad ZammadZammad is missing authorization in ticket create endpoint

Risk 41
Severity
6.9
First published (updated )

Zammad ZammadZammad has Cross-site request forgery (CSRF) in OAuth callback endpoints

Risk 37
Severity
5.9
First published (updated )

Zammad ZammadZammad has an origin validation error in SSO mechanism

Risk 22
Severity
2.3
First published (updated )

Zammad ZammadZammad has a Server-side request forgery (SSRF) via webhooks

Risk 48
Severity
8.3
First published (updated )

Zammad ZammadZammad improperly neutralizes of script-related HTML tags in ticket articles

Risk 38
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zammad ZammadZammad has an information disclosure in ticket detail view of customers in shared organizations

Risk 33
Severity
2.1
First published (updated )

Zammad ZammadSSRF

Risk 15
Severity
4.1
EPSS
0.04%
First published (updated )

Zammad ZammadIn Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changin…

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )

Zammad ZammadIn Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use…

Risk 16
Severity
4.3
EPSS
0.02%
First published (updated )

Zammad ZammadIn Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and w…

Risk 43
Severity
8.1
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zammad ZammadZammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and applicat…

Risk 22
Severity
4.3
First published (updated )

Zammad ZammadCode Injection

Risk 60
Severity
6.7
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have ac…

Risk 45
Severity
8.6
EPSS
0.04%
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially gue…

Risk 47
Severity
9.1
EPSS
0.04%
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial…

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zammad ZammadAn issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address v…

Risk 43
Severity
7.5
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answ…

Risk 22
Severity
4.3
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish…

Risk 35
Severity
5.9
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its…

Risk 27
Severity
5.3
First published (updated )

Zammad ZammadAn issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated …

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zammad ZammadAn issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address …

Risk 40
Severity
6.5
First published (updated )

Zammad ZammadZammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker coul…

Risk 38
Severity
6.5
First published (updated )

Zammad ZammadZammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker w…

Risk 38
Severity
6.5
First published (updated )

Zammad ZammadInsufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform cha…

Risk 22
Severity
4.3
First published (updated )

Zammad ZammadAn issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agen…

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203