Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-44229

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 4.0%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-44229


Contact Us

Shodan ® - All rights reserved