Zammad Gmbh Zammad vulnerabilities
3 known vulnerabilities affecting zammad_gmbh/zammad.
Total CVEs
3
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-102489P1CRITICALCVSS 9.8KEV≥ 6.3.0, < 6.5.42026-09-30
CVE-2026-102489 [CRITICAL] CWE-384 CVE-2026-102489: Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote co
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
nvd
CVE-2026-102490P1CRITICALCVSS 9.8KEV≥ 1.5.0, < 7.1.0-alpha2026-09-30
CVE-2026-102490 [CRITICAL] CWE-269 CVE-2026-102490: All versions of Zammad including the latest alpha enable the local zammad user to escalate privilege
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
nvd
CVE-2019-1010018P4MEDIUMCVSS 6.1v≤ 2.3.0 [fixed: 2.3.1v2.2.2 and 2.1.3]2019-07-16
CVE-2019-1010018 [MEDIUM] CWE-80 CVE-2019-1010018: Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3.
nvd