
Security advisories / CVE references for osTicket 1.18.3 (CVE-2026-38444, 38446, 38447)
Coordinated vulnerability disclosures and CVE references published by Anindya Sankar Roy (GitHub: @fr3akhacks).
Each entry below links to a public advisory containing the affected product, affected/fixed version(s), CVE ID, prose description, vulnerability type, root cause, and impact.
| CVE ID | Title | Type | CWE | CVSS 3.1 | Affected |
|---|---|---|---|---|---|
| CVE-2026-38444 | Stored XSS via email From-header display name | Stored XSS | CWE-79 | 8.1 | osTicket <= 1.18.3 |
| CVE-2026-38446 | Stored XSS via thread entry title | Stored XSS | CWE-79 | 7.6 | osTicket <= 1.18.3 |
| CVE-2026-38447 | Weak API key generation (MD5 + predictable inputs) | Broken crypto | CWE-327, CWE-338 | 5.9 | osTicket <= 1.18.3 |