Published issues
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.zammad-py
- python313Packages.zammad-py
- python314Packages.zammad-py
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Zammad has Cross-site request forgery (CSRF) in OAuth callback endpoints
zammad
-
==>= 7.0.0-alpha, < 7.0.1
-
==< 6.5.4
Permalink
CVE-2026-40026
4.4 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
sleuthkit
-
=<4.14.0
-
==a95b0ac21733b059a517aaefa667a17e1bcbdee1
Permalink
CVE-2026-39844
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.nicegui-highcharts
- python313Packages.nicegui-highcharts
- python314Packages.nicegui-highcharts
5 months, 1 week ago
NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.zammad-py
- python313Packages.zammad-py
- python314Packages.zammad-py
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Zammad is miissing authorization in AI assistance controller for context data used in text tools
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.zammad-py
- python313Packages.zammad-py
- python314Packages.zammad-py
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Zammad has a Server-side request forgery (SSRF) via webhooks
zammad
-
==>= 7.0.0-alpha, < 7.0.1
-
==< 6.5.4
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.zammad-py
- python313Packages.zammad-py
- python314Packages.zammad-py
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Zammad improperly neutralizes of script-related HTML tags in ticket articles
zammad
-
==>= 7.0.0-alpha, < 7.0.1
-
==< 6.5.4
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.zammad-py
- python313Packages.zammad-py
- python314Packages.zammad-py
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Zammad has an origin validation error in SSO mechanism
zammad
-
==>= 7.0.0-alpha, < 7.0.1
-
==< 6.5.4
Permalink
CVE-2026-40024
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Sleuth Kit tsk_recover Path Traversal
sleuthkit
-
=<4.14.0
-
==a3f96b3bc36a8bb1a00c297f77110d4a6e7dd31b
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- python312Packages.zammad-py
- python313Packages.zammad-py
- python314Packages.zammad-py
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Zammad has improper access control in AI assistance controller for text tools
Permalink
CVE-2026-40025
4.4 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
sleuthkit
-
=<4.14.0
-
==8b9c9e7d493bd68624f3b1a3963edd45c3ff7611