Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
redmine redmine vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-47258
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS in a Markdown formatter.
Redmine Redmine
6.1
CVSSv3
CVE-2023-47259
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS in the Textile formatter.
Redmine Redmine
6.1
CVSSv3
CVE-2023-47260
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS via thumbnails.
Redmine Redmine
9.8
CVSSv3
CVE-2023-31541
A unrestricted file upload vulnerability exists in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
Ckeditor Ckeditor 1.2.3
6.1
CVSSv3
CVE-2022-44031
Redmine prior to 4.2.9 and 5.0.x prior to 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
Redmine Redmine
6.1
CVSSv3
CVE-2022-44637
Redmine prior to 4.2.9 and 5.0.x prior to 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
Redmine Redmine
7.5
CVSSv3
CVE-2022-44030
Redmine 5.x prior to 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
Redmine Redmine
5.3
CVSSv3
CVE-2021-42326
Redmine prior to 4.1.5 and 4.2.x prior to 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Redmine Redmine
Debian Debian Linux 9.0
7.5
CVSSv3
CVE-2021-37156
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
Redmine Redmine 4.2.0
Redmine Redmine 4.2.1
5.3
CVSSv3
CVE-2021-31866
Redmine prior to 4.0.9 and 4.1.x prior to 4.1.3 allows an malicious user to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
Redmine Redmine
Debian Debian Linux 9.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »