Tickets
49 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Tickets, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Tickets CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 47 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 49 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High13
- Medium35
Latest CVEs
The 15 most recently published vulnerabilities affecting Tickets.
- CVE-2026-48249Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in rm/incs/mobile_login.inc.php5.9
- CVE-2026-48248Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/login.inc.php5.9
- CVE-2026-48247Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/functions.inc.php5.9
- CVE-2026-48246Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in ajax/reports.php5.9
- CVE-2026-48245Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.php5.3
- CVE-2026-48244Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php5.3
- CVE-2026-48243Open ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.php5.3
- CVE-2026-48242Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in import_mdb.php8.1
- CVE-2026-48241Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.php8.1
- CVE-2026-48240Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters7.1
- CVE-2026-48239Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter7.1
- CVE-2026-48238Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter7.1
- CVE-2026-48237Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters7.1
- CVE-2026-48236Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters7.1
- CVE-2026-48235Open ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker Data8.2
Product grouping is registry-driven, with AI assist and human review. How it works