Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Redmine MEDIUM 6.1
CVE-2023-47258

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

Fix: 4.2.11 / 5.0.6+
Fix from $1,600 2023-11-05
Redmine MEDIUM 6.1
CVE-2023-47259

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

Fix: 4.2.11 / 5.0.6+
Fix from $1,600 2023-11-05
Redmine MEDIUM 6.1
CVE-2023-47260

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

Fix: 4.2.11 / 5.0.6+
Fix from $1,600 2023-11-05
Redmine MEDIUM 6.1
CVE-2022-44031

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in T…

Fix: 4.2.9 / 5.0.4+
Fix from $1,600 2022-12-12
Redmine MEDIUM 6.1
CVE-2022-44637

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatte…

Fix: 4.2.9 / 5.0.4+
Fix from $1,600 2022-12-12
Redmine HIGH 7.5
CVE-2022-44030

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the…

Fix: after 5.0.3
Fix from $1,950 2022-12-06
Redmine HIGH 7.5
CVE-2021-37156

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended beh…

Mitigation only
Fix from $1,950 2021-08-05
Redmine MEDIUM 6.1
CVE-2021-29274

Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

Fix: 4.1.2+
Fix from $1,600 2021-03-29
Redmine MEDIUM 6.1
CVE-2019-17427

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

Fix: 3.4.11 / 4.0.4+
Fix from $1,600 2019-10-10
Redmine MEDIUM 6.1
CVE-2016-10515

In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.

Fix: after 3.2.2
Fix from $1,600 2017-10-18
Redmine MEDIUM 6.1
CVE-2015-8477

Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving…

Fix: after 2.6.1
Fix from $1,600 2017-05-23
Redmine Git Hosting Plugin HIGH 7.5
CVE-2013-4663

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters i…

No fix yet
Fix from $1,950 2014-12-28
Redmine MEDIUM 5.8
CVE-2014-1985

Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x b…

Fix: after 2.4.4
Fix from $1,600 2014-04-11
Redmine HIGH 7.5
CVE-2011-4929EPSS 46%

Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary comma…

Mitigation only
Fix from $1,950 2012-10-08
Redmine MEDIUM 5.0
CVE-2012-2054

Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set at…

Fix: after 1.3.1
Fix from $1,600 2012-04-05
Redmine MEDIUM 6.8
CVE-2009-4079

Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for reques…

Fix: after 0.8.5
Fix from $1,600 2009-11-25