Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-disclosures — Security advisories / CVE references for osTicket 1.18.3 (CVE-2026-38444, 38446, 38447) | Kitploit
Tools/GitHubGitHub/fr3akhacks/cve-disclosures
Vulnerability ScannersVulnerability AnalysisWeb SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubfr3akhacks/cve-disclosures

cve-disclosures

Security advisories / CVE references for osTicket 1.18.3 (CVE-2026-38444, 38446, 38447)

View Repository
2 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE Disclosures

Coordinated vulnerability disclosures and CVE references published by Anindya Sankar Roy (GitHub: @fr3akhacks).

Each entry below links to a public advisory containing the affected product, affected/fixed version(s), CVE ID, prose description, vulnerability type, root cause, and impact.

osTicket (Enhancesoft LLC)

CVE IDTitleTypeCWECVSS 3.1Affected
CVE-2026-38444Stored XSS via email From-header display nameStored XSSCWE-798.1osTicket <= 1.18.3
CVE-2026-38446Stored XSS via thread entry titleStored XSSCWE-797.6osTicket <= 1.18.3
CVE-2026-38447Weak API key generation (MD5 + predictable inputs)Broken cryptoCWE-327, CWE-3385.9osTicket <= 1.18.3
Download Tool