Common Vulnerabilities and Exposures (CVE)

CVE-2026-48240

May 21, 2026 17:57:46 UTC

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are concatenated into WHERE clauses of SELECT statements in the statistics rollup queries without ...

CVE-2026-48215

May 21, 2026 17:56:06 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_id POST parameter direc...

CVE-2026-48221

May 21, 2026 17:55:43 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter...

CVE-2026-48227

May 21, 2026 17:55:21 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id and ticket_id GET param...

CVE-2026-48223

May 21, 2026 17:54:42 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST paramete...

CVE-2026-48234

May 21, 2026 17:53:51 UTC

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort and dir GET parameters are concatenated into the ORDER BY clause of a SELECT statement without sanitization. Authenticate...

CVE-2026-48217

May 21, 2026 17:53:12 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parame...

CVE-2026-48228

May 21, 2026 17:52:42 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id and ticket_id GET par...

CVE-2026-48222

May 21, 2026 17:51:52 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter ...

CVE-2026-48216

May 21, 2026 17:51:15 UTC

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parameters...

CVE-2026-48233

May 21, 2026 17:48:04 UTC

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET parameter is concatenated into the LIMIT clause of a SELECT statement without sanitization. Authenticated attackers can cr...

CVE-2026-48239

May 21, 2026 17:47:44 UTC

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into the WHERE clause of SELECT statements in the incidents summary report without sanitization. Aut...

CVE-2026-48245

May 21, 2026 17:47:25 UTC

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform ...

CVE-2026-28764

May 21, 2026 17:41:28 UTC

MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability

CVE-2026-22554

May 21, 2026 16:53:30 UTC

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability