Home/Product/znuny
Product

znuny

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-26846
>= 6.0.0 and <= 6.0.48
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update tic
9.8CRITICAL
CVE-2025-26847
>= 7.0.1 and <= 7.1.6
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
7.5HIGH
CVE-2025-26845
>= 7.0.1 and <= 7.1.3
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to
9.8CRITICAL
CVE-2025-43926
<= 6.5.14
An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subact
6.1MEDIUM
CVE-2025-26844
<= 7.1.3
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
9.8CRITICAL
CVE-2025-26842
<= 7.1.3
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail message
7.5HIGH
CVE-2024-48938
>= 7.0.1 and <= 7.0.16
Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTM
7.5HIGH
CVE-2024-48937
>= 7.0.1 and <= 7.0.16
Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA fie
6.1MEDIUM
CVE-2024-32493
>= 7.0.1 and <= 7.0.16
An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject
8.8HIGH
CVE-2024-32492
>= 7.0.1 and <= 7.0.16
An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of e
7.1HIGH
CVE-2024-32491
>= 7.0.1 and <= 7.0.16
An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can uplo
9.8CRITICAL
threatengine.sh