CVE-2026-6841 PUBLISHED

Reflected XSS in Request Tracker

Assigner: CERT-PL
Reserved: 22.04.2026 Published: 21.05.2026 Updated: 21.05.2026

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser.

This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Best Practical
Product Request Tracker
Versions Default: unaffected
  • affected from 5.0.4 to 5.0.10 (excl.)
  • affected from 6.0.0 to 6.0.3 (excl.)

Credits

  • Aleksander Iwicki (CERT Polska) finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS