bestpractical records
73 published records for vendor bestpractical.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 83.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-255 Credentials Management Errors4
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-310 Cryptographic Issues4
The weakness classes this vendor ships most often: where to look.
CWEAll records
73 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2017-5944No exploit | The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remobestpractical · request tracker · CWE-20 | High8.8 | — | 2.8% | Jul 3, 2017 |
36Monitor | CVE-2022-25801No exploit | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.bestpractical · request tracker for incident response · CWE-918 | Critical9.1 | — | 0.9% | Jul 14, 2022 |
36Monitor | CVE-2022-25800No exploit | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.bestpractical · request tracker for incident response · CWE-918 | Critical9.1 | — | 0.9% | Jul 14, 2022 |
36Monitor | CVE-2026-44231No exploit | RT: Privilege escalation and information disclosure via REST 2.0 user collection endpointbestpractical · request tracker · CWE-200 | Critical9.1 | — | 0.4% | Jul 20, 2026 |
35Monitor | CVE-2017-5943No exploit | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information bestpractical · request tracker · CWE-352 | High8.8 | — | 0.8% | Jul 3, 2017 |
31Monitor | CVE-2011-5092No exploit | Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges vbestpractical · rt · CWE-264 | High7.5 | — | 2.8% | Jun 4, 2012 |
31Monitor | CVE-2013-3525Proof of concept | SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commanbestpractical · request tracker · CWE-89 | High7.5 | — | 2.8% | May 10, 2013 |
31Monitor | CVE-2018-18898No exploit | The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algoritbestpractical · request tracker · CWE-400 | High7.5 | — | 2.4% | Mar 21, 2019 |
31Monitor | CVE-2021-38562No exploit | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a bestpractical · request tracker · CWE-203 | High7.5 | — | 1.8% | Oct 18, 2021 |
30Monitor | CVE-2023-41259No exploit | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in bestpractical · request tracker · CWE-200 | High7.5 | — | 0.7% | Nov 3, 2023 |
30Monitor | CVE-2023-41260No exploit | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API callbestpractical · request tracker · CWE-200 | High7.5 | — | 0.7% | Nov 3, 2023 |
30Monitor | CVE-2023-45024No exploit | Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.bestpractical · request tracker · CWE-200 | High7.5 | — | 0.6% | Nov 3, 2023 |
29Monitor | CVE-2014-9472No exploit | The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a dendebian · debian linux · CWE-399 | High7.1 | — | 2.8% | Mar 9, 2015 |
28Monitor | CVE-2011-4458No exploit | Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enablbestpractical · rt · CWE-94 | Medium6.8 | — | 3.1% | Jun 4, 2012 |
28Monitor | CVE-2013-3370No exploit | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allbestpractical · rt · CWE-264 | Medium6.8 | — | 2.3% | Aug 23, 2013 |
27Monitor | CVE-2011-5093No exploit | Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated ubestpractical · rt · CWE-264 | Medium6.5 | — | 2.1% | Jun 4, 2012 |
27Monitor | CVE-2011-4460No exploit | SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users bestpractical · rt · CWE-89 | Medium6.5 | — | 1.8% | Jun 4, 2012 |
27Monitor | CVE-2011-2085No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote atbestpractical · rt · CWE-352 | Medium6.8 | — | 1.1% | Jun 4, 2012 |
27Monitor | CVE-2012-4732No exploit | Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versionbestpractical · rt · CWE-352 | Medium6.8 | — | 0.9% | Nov 11, 2012 |
26Monitor | CVE-2015-1464No exploit | RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.fedoraproject · fedora · CWE-284 | Medium6.4 | — | 2.0% | Mar 9, 2015 |
26Monitor | CVE-2011-1686No exploit | Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rcbestpractical · rt · CWE-89 | Medium6.5 | — | 1.3% | Apr 22, 2011 |
25Monitor | CVE-2012-6579No exploit | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryptibestpractical · request tracker · CWE-310 | Medium6.4 | — | 0.8% | Jul 24, 2013 |
24Monitor | CVE-2009-3585No exploit | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.bestpractical · rt · CWE-287 | Medium5.8 | — | 2.7% | Dec 2, 2009 |
24Monitor | CVE-2009-4151No exploit | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.bestpractical · rt · CWE-287 | Medium5.8 | — | 1.8% | Dec 2, 2009 |
24Monitor | CVE-2012-4733No exploit | Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allowsbestpractical · rt · CWE-255 | Medium6.0 | — | 1.6% | Aug 23, 2013 |
- CVE-2017-594436Monitor
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remo
HighCVSS 8.8No exploitEPSS 3%bestpractical · request trackerJul 3, 2017
- CVE-2022-2580136Monitor
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
CriticalCVSS 9.1No exploitEPSS 1%bestpractical · request tracker for incident responseJul 14, 2022
- CVE-2022-2580036Monitor
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
CriticalCVSS 9.1No exploitEPSS 1%bestpractical · request tracker for incident responseJul 14, 2022
- CVE-2026-4423136Monitor
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
CriticalCVSS 9.1No exploitEPSS 0%bestpractical · request trackerJul 20, 2026
- CVE-2017-594335Monitor
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information
HighCVSS 8.8No exploitEPSS 1%bestpractical · request trackerJul 3, 2017
- CVE-2011-509231Monitor
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges v
HighCVSS 7.5No exploitEPSS 3%bestpractical · rtJun 4, 2012
- CVE-2013-352531Monitor
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL comman
HighCVSS 7.5Proof of conceptEPSS 3%bestpractical · request trackerMay 10, 2013
- CVE-2018-1889831Monitor
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorit
HighCVSS 7.5No exploitEPSS 2%bestpractical · request trackerMar 21, 2019
- CVE-2021-3856231Monitor
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a
HighCVSS 7.5No exploitEPSS 2%bestpractical · request trackerOct 18, 2021
- CVE-2023-4125930Monitor
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in
HighCVSS 7.5No exploitEPSS 1%bestpractical · request trackerNov 3, 2023
- CVE-2023-4126030Monitor
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API call
HighCVSS 7.5No exploitEPSS 1%bestpractical · request trackerNov 3, 2023
- CVE-2023-4502430Monitor
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
HighCVSS 7.5No exploitEPSS 1%bestpractical · request trackerNov 3, 2023
- CVE-2014-947229Monitor
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a den
HighCVSS 7.1No exploitEPSS 3%debian · debian linuxMar 9, 2015
- CVE-2011-445828Monitor
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabl
MediumCVSS 6.8No exploitEPSS 3%bestpractical · rtJun 4, 2012
- CVE-2013-337028Monitor
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which all
MediumCVSS 6.8No exploitEPSS 2%bestpractical · rtAug 23, 2013
- CVE-2011-509327Monitor
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated u
MediumCVSS 6.5No exploitEPSS 2%bestpractical · rtJun 4, 2012
- CVE-2011-446027Monitor
SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users
MediumCVSS 6.5No exploitEPSS 2%bestpractical · rtJun 4, 2012
- CVE-2011-208527Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote at
MediumCVSS 6.8No exploitEPSS 1%bestpractical · rtJun 4, 2012
- CVE-2012-473227Monitor
Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other version
MediumCVSS 6.8No exploitEPSS 1%bestpractical · rtNov 11, 2012
- CVE-2015-146426Monitor
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
MediumCVSS 6.4No exploitEPSS 2%fedoraproject · fedoraMar 9, 2015
- CVE-2011-168626Monitor
Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc
MediumCVSS 6.5No exploitEPSS 1%bestpractical · rtApr 22, 2011
- CVE-2012-657925Monitor
Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encrypti
MediumCVSS 6.4No exploitEPSS 1%bestpractical · request trackerJul 24, 2013
- CVE-2009-358524Monitor
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.
MediumCVSS 5.8No exploitEPSS 3%bestpractical · rtDec 2, 2009
- CVE-2009-415124Monitor
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.
MediumCVSS 5.8No exploitEPSS 2%bestpractical · rtDec 2, 2009
- CVE-2012-473324Monitor
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows
MediumCVSS 6.0No exploitEPSS 2%bestpractical · rtAug 23, 2013