Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-47258 Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter. Redmine 4.2.11 / 5.0.6+ Fix from $1,6002023-11-05 MEDIUM 6.1 CVE-2023-47259 Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter. Redmine 4.2.11 / 5.0.6+ Fix from $1,6002023-11-05 MEDIUM 6.1 CVE-2023-47260 Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails. Redmine 4.2.11 / 5.0.6+ Fix from $1,6002023-11-05 MEDIUM 6.1 CVE-2022-44031 Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in T… Redmine 4.2.9 / 5.0.4+ Fix from $1,6002022-12-12 MEDIUM 6.1 CVE-2022-44637 Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatte… Redmine 4.2.9 / 5.0.4+ Fix from $1,6002022-12-12 HIGH 7.5 CVE-2022-44030 Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the… Redmine after 5.0.3 Fix from $1,9502022-12-06 HIGH 7.5 CVE-2021-37156 Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended beh… Redmine Mitigation only Fix from $1,9502021-08-05 MEDIUM 6.1 CVE-2021-29274 Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip. Redmine 4.1.2+ Fix from $1,6002021-03-29 MEDIUM 6.1 CVE-2019-17427 In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors. Redmine 3.4.11 / 4.0.4+ Fix from $1,6002019-10-10 MEDIUM 6.1 CVE-2016-10515 In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages. Redmine after 3.2.2 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2015-8477 Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving… Redmine after 2.6.1 Fix from $1,6002017-05-23 HIGH 7.5 CVE-2013-4663 git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters i… Redmine Git Hosting Plugin No fix yet Fix from $1,9502014-12-28 MEDIUM 5.8 CVE-2014-1985 Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x b… Redmine after 2.4.4 Fix from $1,6002014-04-11 HIGH 7.5 CVE-2011-4929EPSS 46% Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary comma… Redmine Mitigation only Fix from $1,9502012-10-08 MEDIUM 5.0 CVE-2012-2054 Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set at… Redmine after 1.3.1 Fix from $1,6002012-04-05 MEDIUM 6.8 CVE-2009-4079 Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for reques… Redmine after 0.8.5 Fix from $1,6002009-11-25