Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
redmine vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2017-15568
In Redmine prior to 3.2.8, 3.3.x prior to 3.3.5, and 3.4.x prior to 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.
Redmine Redmine 3.4.0
Redmine Redmine 3.4.1
Redmine Redmine 3.3.0
Redmine Redmine 3.3.2
Redmine Redmine 3.3.3
Redmine Redmine 3.3.4
Redmine Redmine
Redmine Redmine 3.4.2
Redmine Redmine 3.3.1
Debian Debian Linux 9.0
6.1
CVSSv3
CVE-2017-15569
In Redmine prior to 3.2.8, 3.3.x prior to 3.3.5, and 3.4.x prior to 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.
Redmine Redmine
Redmine Redmine 3.3.1
Redmine Redmine 3.3.3
Redmine Redmine 3.4.0
Redmine Redmine 3.4.1
Redmine Redmine 3.4.2
Redmine Redmine 3.3.0
Redmine Redmine 3.3.2
Redmine Redmine 3.3.4
Debian Debian Linux 9.0
6.1
CVSSv3
CVE-2017-15570
In Redmine prior to 3.2.8, 3.3.x prior to 3.3.5, and 3.4.x prior to 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
Redmine Redmine 3.4.1
Redmine Redmine 3.4.2
Redmine Redmine 3.3.0
Redmine Redmine 3.3.1
Redmine Redmine 3.4.0
Redmine Redmine 3.3.2
Redmine Redmine 3.3.4
Redmine Redmine 3.3.3
Redmine Redmine
Debian Debian Linux 9.0
6.1
CVSSv3
CVE-2017-15571
In Redmine prior to 3.2.8, 3.3.x prior to 3.3.5, and 3.4.x prior to 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
Redmine Redmine 3.4.0
Redmine Redmine 3.3.4
Redmine Redmine 3.4.2
Redmine Redmine 3.3.0
Redmine Redmine 3.3.1
Redmine Redmine 3.3.2
Redmine Redmine 3.4.1
Redmine Redmine 3.3.3
Redmine Redmine
Debian Debian Linux 9.0
5.3
CVSSv3
CVE-2015-8346
app/views/timelog/_form.html.erb in Redmine prior to 2.6.8, 3.0.x prior to 3.0.6, and 3.1.x prior to 3.1.2 allows remote malicious users to obtain sensitive information about subjects of issues by viewing the time logging form.
Redmine Redmine 3.1.1
Redmine Redmine 3.1.0
Redmine Redmine 3.0.5
Redmine Redmine 3.0.2
Redmine Redmine 3.0.0
Redmine Redmine 3.0.1
Redmine Redmine
Redmine Redmine 3.0.3
Redmine Redmine 3.0.4
Debian Debian Linux 8.0
4.3
CVSSv3
CVE-2015-8473
The Issues API in Redmine prior to 2.6.8, 3.0.x prior to 3.0.6, and 3.1.x prior to 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
Debian Debian Linux 8.0
Redmine Redmine 3.1.0
Redmine Redmine 3.1.1
Redmine Redmine 3.0.4
Redmine Redmine 3.0.2
Redmine Redmine 3.0.0
Redmine Redmine 3.0.1
Redmine Redmine
Redmine Redmine 3.0.5
Redmine Redmine 3.0.3
NA
CVE-2014-1985
Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine prior to 2.4.5 and 2.5.x prior to 2.5.1 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th...
Redmine Redmine 2.4.2
Redmine Redmine 2.4.1
Redmine Redmine
Redmine Redmine 2.4.3
Redmine Redmine 2.4.0
Redmine Redmine 2.5.0
NA
CVE-2011-4927
Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x prior to 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.
Redmine Redmine 1.0.3
Redmine Redmine 1.0.4
Redmine Redmine 1.0.1
Redmine Redmine 1.0.0
Redmine Redmine 1.0.2
7.4
CVSSv3
CVE-2015-8474
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine prior to 2.6.7, 3.0.x prior to 3.0.5, and 3.1.x prior to 3.1.1 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks vi...
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Redmine Redmine 3.1.0
Redmine Redmine 3.0.4
Redmine Redmine 3.0.3
Redmine Redmine 2.5.1
Redmine Redmine 3.0.0
Redmine Redmine 3.0.2
Redmine Redmine 3.0.1
Redmine Redmine
4.3
CVSSv3
CVE-2017-16804
In Redmine prior to 3.2.7 and 3.3.x prior to 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.
Redmine Redmine 3.3.1
Redmine Redmine 3.3.3
Redmine Redmine
Redmine Redmine 3.3.0
Redmine Redmine 3.3.2
Debian Debian Linux 9.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »