Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The Zammad GUI is rendering this content, due to applied CSP rules no harm was done by e.g., clicking such a link. This vulnerability is fixed in 7.0.1 and 6.5.4.
Cite this page
CVE-2026-34718. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-34718
Use CWE-80, Zammad vendor hub and Zammad product page to widen CVE-2026-34718 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34724, CVE-2026-34723 and CVE-2026-34719 for nearby disclosures in the same product family.