CVE-2026-97735

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

  • Published Sep 25, 2026
  • CVSS 8.0 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-97735 at the National Vulnerability Database