zammad records
90 published records for vendor zammad.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 14.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-863 Incorrect Authorization8
- CWE-862 Missing Authorization7
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-284 Improper Access Control3
The weakness classes this vendor ships most often: where to look.
CWEAll records
90 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-42090No exploit | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-502 | Critical9.8 | — | 2.3% | Oct 7, 2021 |
40Plan | CVE-2021-42094No exploit | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-77 | Critical9.8 | — | 1.9% | Oct 7, 2021 |
39Monitor | CVE-2017-5619No exploit | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.zammad · zammad · CWE-287 | Critical9.8 | — | 1.5% | Mar 13, 2017 |
39Monitor | CVE-2020-26030No exploit | An issue was discovered in Zammad before 3.4.1.zammad · zammad · CWE-287 | Critical9.8 | — | 1.4% | Dec 28, 2020 |
39Monitor | CVE-2022-48021No exploit | A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.zammad · zammad | Critical9.8 | — | 0.9% | Feb 2, 2023 |
39Monitor | CVE-2022-35490No exploit | Zammad 5.2.0 is vulnerable to privilege escalation.zammad · zammad · CWE-307 | Critical9.8 | — | 0.9% | Aug 8, 2022 |
39Monitor | CVE-2017-6080No exploit | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involvizammad · zammad · CWE-352 | Critical9.8 | — | 0.7% | Mar 13, 2017 |
36Monitor | CVE-2022-27332No exploit | An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.zammad · zammad · CWE-306 | Critical9.1 | — | 1.1% | Apr 26, 2022 |
36Monitor | CVE-2021-42091No exploit | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-918 | Critical9.1 | — | 1.1% | Oct 7, 2021 |
36Monitor | CVE-2024-33668No exploit | An issue was discovered in Zammad before 6.3.0.zammad · zammad · CWE-639 | Critical9.1 | — | 0.4% | Apr 25, 2024 |
35Monitor | CVE-2021-42086No exploit | An issue was discovered in Zammad before 4.1.1.zammad · zammad | High8.8 | — | 1.1% | Oct 7, 2021 |
35Monitor | CVE-2017-6081No exploit | A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.zammad · zammad · CWE-352 | High8.8 | — | 0.6% | Mar 13, 2017 |
35Monitor | CVE-2025-32359No exploit | In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security.zammad · zammad · CWE-602 | High8.8 | — | 0.3% | Apr 5, 2025 |
34Monitor | CVE-2026-34723No exploit | Zammad has incorrect access control in getting_started_controllerzammad · zammad · CWE-284 | High8.7 | — | 0.5% | Apr 8, 2026 |
34Monitor | CVE-2024-33666No exploit | An issue was discovered in Zammad before 6.3.0.zammad · zammad · CWE-284 | High8.6 | — | 0.5% | Apr 25, 2024 |
34Monitor | CVE-2026-34724Proof of concept | Zammad has a server-side template injection leading to RCE via AI Agentzammad · zammad · CWE-94 | High8.7 | — | 0.5% | Apr 8, 2026 |
33Monitor | CVE-2026-34719No exploit | Zammad has a Server-side request forgery (SSRF) via webhookszammad · zammad · CWE-918 | High8.3 | — | 0.3% | Apr 8, 2026 |
32Monitor | CVE-2021-43145No exploit | With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.zammad · zammad | High8.1 | — | 1.0% | Feb 4, 2022 |
32Monitor | CVE-2025-32360No exploit | In Zammad 6.4.x before 6.4.2, there is information exposure.zammad · zammad · CWE-402 | High8.1 | — | 0.2% | Apr 5, 2025 |
30Monitor | CVE-2020-10096No exploit | An issue was discovered in Zammad 3.0 through 3.2.zammad · zammad · CWE-200 | High7.5 | — | 1.1% | Mar 4, 2020 |
30Monitor | CVE-2021-35299No exploit | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration prozammad · zammad · CWE-532 | High7.5 | — | 1.1% | Jun 28, 2021 |
30Monitor | CVE-2021-42089No exploit | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-200 | High7.5 | — | 1.1% | Oct 7, 2021 |
30Monitor | CVE-2020-10101No exploit | An issue was discovered in Zammad 3.0 through 3.2.zammad · zammad · CWE-20 | High7.5 | — | 1.1% | Mar 4, 2020 |
30Monitor | CVE-2020-26032No exploit | An SSRF issue was discovered in Zammad before 3.4.1.zammad · zammad · CWE-918 | High7.5 | — | 1.1% | Dec 28, 2020 |
30Monitor | CVE-2022-29701No exploit | A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests forzammad · zammad · CWE-770 | High7.5 | — | 1.0% | Apr 26, 2022 |
- CVE-2021-4209040Plan
An issue was discovered in Zammad before 4.1.1.
CriticalCVSS 9.8No exploitEPSS 2%zammad · zammadOct 7, 2021
- CVE-2021-4209440Plan
An issue was discovered in Zammad before 4.1.1.
CriticalCVSS 9.8No exploitEPSS 2%zammad · zammadOct 7, 2021
- CVE-2017-561939Monitor
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.
CriticalCVSS 9.8No exploitEPSS 2%zammad · zammadMar 13, 2017
- CVE-2020-2603039Monitor
An issue was discovered in Zammad before 3.4.1.
CriticalCVSS 9.8No exploitEPSS 1%zammad · zammadDec 28, 2020
- CVE-2022-4802139Monitor
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.
CriticalCVSS 9.8No exploitEPSS 1%zammad · zammadFeb 2, 2023
- CVE-2022-3549039Monitor
Zammad 5.2.0 is vulnerable to privilege escalation.
CriticalCVSS 9.8No exploitEPSS 1%zammad · zammadAug 8, 2022
- CVE-2017-608039Monitor
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involvi
CriticalCVSS 9.8No exploitEPSS 1%zammad · zammadMar 13, 2017
- CVE-2022-2733236Monitor
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.
CriticalCVSS 9.1No exploitEPSS 1%zammad · zammadApr 26, 2022
- CVE-2021-4209136Monitor
An issue was discovered in Zammad before 4.1.1.
CriticalCVSS 9.1No exploitEPSS 1%zammad · zammadOct 7, 2021
- CVE-2024-3366836Monitor
An issue was discovered in Zammad before 6.3.0.
CriticalCVSS 9.1No exploitEPSS 0%zammad · zammadApr 25, 2024
- CVE-2021-4208635Monitor
An issue was discovered in Zammad before 4.1.1.
HighCVSS 8.8No exploitEPSS 1%zammad · zammadOct 7, 2021
- CVE-2017-608135Monitor
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.
HighCVSS 8.8No exploitEPSS 1%zammad · zammadMar 13, 2017
- CVE-2025-3235935Monitor
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security.
HighCVSS 8.8No exploitEPSS 0%zammad · zammadApr 5, 2025
- CVE-2026-3472334Monitor
Zammad has incorrect access control in getting_started_controller
HighCVSS 8.7No exploitEPSS 1%zammad · zammadApr 8, 2026
- CVE-2024-3366634Monitor
An issue was discovered in Zammad before 6.3.0.
HighCVSS 8.6No exploitEPSS 1%zammad · zammadApr 25, 2024
- CVE-2026-3472434Monitor
Zammad has a server-side template injection leading to RCE via AI Agent
HighCVSS 8.7Proof of conceptEPSS 0%zammad · zammadApr 8, 2026
- CVE-2026-3471933Monitor
Zammad has a Server-side request forgery (SSRF) via webhooks
HighCVSS 8.3No exploitEPSS 0%zammad · zammadApr 8, 2026
- CVE-2021-4314532Monitor
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
HighCVSS 8.1No exploitEPSS 1%zammad · zammadFeb 4, 2022
- CVE-2025-3236032Monitor
In Zammad 6.4.x before 6.4.2, there is information exposure.
HighCVSS 8.1No exploitEPSS 0%zammad · zammadApr 5, 2025
- CVE-2020-1009630Monitor
An issue was discovered in Zammad 3.0 through 3.2.
HighCVSS 7.5No exploitEPSS 1%zammad · zammadMar 4, 2020
- CVE-2021-3529930Monitor
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration pro
HighCVSS 7.5No exploitEPSS 1%zammad · zammadJun 28, 2021
- CVE-2021-4208930Monitor
An issue was discovered in Zammad before 4.1.1.
HighCVSS 7.5No exploitEPSS 1%zammad · zammadOct 7, 2021
- CVE-2020-1010130Monitor
An issue was discovered in Zammad 3.0 through 3.2.
HighCVSS 7.5No exploitEPSS 1%zammad · zammadMar 4, 2020
- CVE-2020-2603230Monitor
An SSRF issue was discovered in Zammad before 3.4.1.
HighCVSS 7.5No exploitEPSS 1%zammad · zammadDec 28, 2020
- CVE-2022-2970130Monitor
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for
HighCVSS 7.5No exploitEPSS 1%zammad · zammadApr 26, 2022