📦 Zammad

by Zammad

🔍 What is Zammad?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33668

CRITICAL CVSS 9.1 Apr 26, 2024

This vulnerability in Zammad allows attackers to brute-force guessable FormIDs used in the upload cache, enabling them to inject malicious content into article drafts they shouldn't have access to. Al...

CVE-2022-48021

CRITICAL CVSS 9.8 Feb 3, 2023

This critical vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges by sending a specially crafted message to the server. All organizations running the affec...

CVE-2022-27332

CRITICAL CVSS 9.1 Apr 27, 2022

CVE-2022-27332 is an authentication bypass vulnerability in Zammad v5.0.3 that allows unauthenticated attackers to write entries to the CTI caller log. This enables attackers to execute phishing attac...

CVE-2021-42090

CRITICAL CVSS 9.8 Oct 7, 2021

CVE-2021-42090 is a remote code execution vulnerability in Zammad's Form functionality due to unsafe deserialization. Attackers can execute arbitrary code on affected Zammad instances, potentially com...

CVE-2021-42094

CRITICAL CVSS 9.8 Oct 7, 2021

CVE-2021-42094 is a command injection vulnerability in Zammad that allows attackers to execute arbitrary commands on the server via custom Packages. This affects all Zammad installations before versio...

CVE-2020-26030

CRITICAL CVSS 9.8 Dec 28, 2020

This vulnerability allows attackers to bypass authentication in Zammad's SSO endpoint by sending a crafted header when SSO is not configured. Attackers can create authenticated sessions to perform any...

CVE-2024-33666

HIGH CVSS 8.6 Apr 26, 2024

This vulnerability in Zammad allows users with customer-level access to view time accounting details for tickets via the API, which should be restricted to agent-level users only. This exposes sensiti...

CVE-2023-50455

HIGH CVSS 7.5 Dec 10, 2023

This vulnerability in Zammad allows attackers to send excessive email verification requests to known addresses, causing denial of service through email spam and resource exhaustion. Organizations runn...

CVE-2022-29700

HIGH CVSS 7.5 Apr 27, 2022

CVE-2022-29700 is a vulnerability in Zammad v5.1.0 where lack of password length restriction allows attackers to create extremely long passwords, causing Denial of Service (DoS) during password verifi...

CVE-2021-43145

HIGH CVSS 8.1 Feb 4, 2022

Zammad 5.0.1 with certain LDAP configurations allows unauthorized access using existing user accounts. This authentication bypass vulnerability affects organizations using Zammad with LDAP integration...

CVE-2021-42086

HIGH CVSS 8.8 Oct 7, 2021

This vulnerability allows authenticated Agent accounts in Zammad to escalate privileges to Administrator level by modifying account data through crafted requests. It affects all Zammad installations r...

CVE-2021-42089

HIGH CVSS 7.5 Oct 7, 2021

This vulnerability in Zammad's REST API allows unauthorized disclosure of sensitive information. Attackers can access confidential data through API endpoints without proper authentication. Organizatio...

CVE-2021-42093

HIGH CVSS 7.2 Oct 7, 2021

This vulnerability allows authenticated administrators in Zammad to execute arbitrary code on the server by manipulating trigger functionality. It affects Zammad installations where admin users could ...

CVE-2021-35299

HIGH CVSS 7.5 Jun 28, 2021

This vulnerability in Zammad allows attackers to probe email connection configurations and obtain sensitive information like email server credentials. It affects all Zammad installations from version ...

CVE-2025-32358

MEDIUM CVSS 4.0 Apr 5, 2025

This vulnerability allows authenticated admin users in Zammad to perform Server-Side Request Forgery (SSRF) attacks. When webhooks return redirect responses, Zammad automatically follows them with GET...

CVE-2025-32360

MEDIUM CVSS 4.2 Apr 5, 2025

This vulnerability in Zammad allows logged-in customers to view and manipulate shared article drafts intended only for agents. Customers can access confidential information from draft articles and mod...