Home

Description

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.

PUBLISHED Reserved 2026-04-22 | Published 2026-05-21 | Updated 2026-05-21 | Assigner CERT-PL




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

5.0.4 (semver) before 5.0.10
affected

6.0.0 (semver) before 6.0.3
affected

Credits

Aleksander Iwicki (CERT Polska) finder

References

cert.pl/en/posts/2026/05/CVE-2026-6841 third-party-advisory

requesttracker.com/request-tracker/ product

docs.bestpractical.com/release-notes/rt/5.0.10 release-notes

docs.bestpractical.com/release-notes/rt/6.0.3 release-notes

cve.org (CVE-2026-6841)

nvd.nist.gov (CVE-2026-6841)

Download JSON