Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
redmine redmine vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2019-17427
In Redmine prior to 3.4.11 and 4.0.x prior to 4.0.4, persistent XSS exists due to textile formatting errors.
Redmine Redmine
1 Github repository
NA
CVE-2023-47258
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS in a Markdown formatter.
Redmine Redmine
NA
CVE-2022-44637
Redmine prior to 4.2.9 and 5.0.x prior to 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
Redmine Redmine
4.3
CVSSv2
CVE-2015-8477
Cross-site scripting (XSS) vulnerability in Redmine prior to 2.6.2 allows remote malicious users to inject arbitrary web script or HTML via vectors involving flash message rendering.
Redmine Redmine
NA
CVE-2023-47259
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS in the Textile formatter.
Redmine Redmine
NA
CVE-2023-47260
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS via thumbnails.
Redmine Redmine
4.3
CVSSv2
CVE-2016-10515
In Redmine prior to 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
Redmine Redmine
7.5
CVSSv2
CVE-2013-4663
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exist...
Redmine Redmine Git Hosting Plugin -
5
CVSSv2
CVE-2021-42326
Redmine prior to 4.1.5 and 4.2.x prior to 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Redmine Redmine
Debian Debian Linux 9.0
4
CVSSv2
CVE-2019-18890
A SQL injection vulnerability in Redmine up to and including 3.2.9 and 3.3.x prior to 3.3.10 allows Redmine users to access protected information via a crafted object query.
Redmine Redmine
Debian Debian Linux 9.0
2 Github repositories
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »