Bestpractical Request Tracker
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Bestpractical Request Tracker.
By the Year
In 2026 there have been 2 vulnerabilities in Bestpractical Request Tracker with an average score of 2.6 out of ten. Last year, in 2025 Request Tracker had 4 security vulnerabilities published. Right now, Request Tracker is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 3.87
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 2.60 |
| 2025 | 4 | 6.47 |
| 2024 | 0 | 0.00 |
| 2023 | 3 | 7.50 |
| 2022 | 2 | 6.10 |
| 2021 | 1 | 7.50 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 7.50 |
It may take a day or so for new Request Tracker vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Bestpractical Request Tracker Security Vulnerabilities
XSS via Page Param in Request Tracker 5.0.4-5.0.9 / 6.0.0-6.0.2
CVE-2026-6841
- May 21, 2026
Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victims browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
XSS
Request Tracker (RT) <=4.4.9 CSV Injection via TSV Export
CVE-2025-61873
2.6 - Low
- January 16, 2026
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
CSV Injection
RT XSS via JS Injection in Permalink (v5.0–5.0.7)
CVE-2025-31501
6.1 - Medium
- May 28, 2025
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
XSS
Best Practical RT 5.0-5.0.7 XSS via Asset name injection
CVE-2025-31500
6.1 - Medium
- May 28, 2025
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
XSS
XSS in Request Tracker 4.4-4.4.7/5.0-5.0.7 via Search URL Parameters
CVE-2025-30087
7.2 - High
- May 28, 2025
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
XSS
RT 5.x: 3DES in S/MIME Emails Vulnerable Before v5.0.8
CVE-2025-2545
- May 05, 2025
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Use of a Broken or Risky Cryptographic Algorithm
Info Disclosure in RT5 Query Builder (before 5.0.5)
CVE-2023-45024
7.5 - High
- November 03, 2023
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
Best Practical RT <=4.4.6 / <=5.0.4 Info Exposure via mail-gateway REST API
CVE-2023-41260
- November 03, 2023
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
Information Disclosure
RT <4.4.7 / 5.0.5 Inf Disclosure via Spoofed Email Headers
CVE-2023-41259
- November 03, 2023
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
Information Disclosure
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect
CVE-2022-25803
6.1 - Medium
- July 14, 2022
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
Open Redirect
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3
CVE-2022-25802
6.1 - Medium
- July 14, 2022
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
XSS
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2
CVE-2021-38562
7.5 - High
- October 18, 2021
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
Side Channel Attack
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4
CVE-2018-18898
7.5 - High
- March 21, 2019
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
Resource Exhaustion
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier
CVE-2013-3525
- May 10, 2013
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Bestpractical Request Tracker or by Bestpractical? Click the Watch button to subscribe.