Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
redmine vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-44031
Redmine prior to 4.2.9 and 5.0.x prior to 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
Redmine Redmine
NA
CVE-2023-47258
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS in a Markdown formatter.
Redmine Redmine
NA
CVE-2023-47259
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS in the Textile formatter.
Redmine Redmine
NA
CVE-2023-47260
Redmine prior to 4.2.11 and 5.0.x prior to 5.0.6 allows XSS via thumbnails.
Redmine Redmine
383
VMScore
CVE-2021-29274
Redmine 4.1.x prior to 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
Redmine Redmine
383
VMScore
CVE-2019-17427
In Redmine prior to 3.4.11 and 4.0.x prior to 4.0.4, persistent XSS exists due to textile formatting errors.
Redmine Redmine
1 Github repository
NA
CVE-2022-44637
Redmine prior to 4.2.9 and 5.0.x prior to 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
Redmine Redmine
668
VMScore
CVE-2013-4663
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exist...
Redmine Redmine Git Hosting Plugin -
668
VMScore
CVE-2021-30164
Redmine prior to 4.0.8 and 4.1.x prior to 4.1.2 allows malicious users to bypass the add_issue_notes permission requirement by leveraging the Issues API.
Redmine Redmine
Debian Debian Linux 9.0
605
VMScore
CVE-2017-18026
Redmine prior to 3.2.9, 3.3.x prior to 3.3.6, and 3.4.x prior to 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote malicious users to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch wh...
Redmine Redmine
Debian Debian Linux 9.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »