VYPR

Vendor CVEs

Redmine

All CVEs

57 total · sorted by risk
  • CVE-2024-36267HigMay 30, 2024
    risk 0.53cvss 8.1epss 0.01

    Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, a logged-in user may obtain or delete arbitrary files on the server (within the privilege of the Redmine process).

  • CVE-2017-15577HigOct 18, 2017
    risk 0.49cvss 7.5epss 0.02

    Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

  • CVE-2017-15576HigOct 18, 2017
    risk 0.49cvss 7.5epss 0.02

    Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

  • CVE-2017-15572HigOct 18, 2017
    risk 0.49cvss 7.5epss 0.02

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.

  • CVE-2017-15575HigOct 18, 2017
    risk 0.48cvss 7.3epss 0.01

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.

  • CVE-2015-8474HigApr 12, 2016
    risk 0.41cvss 7.4epss 0.02

    Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted…

  • CVE-2017-15574MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

  • CVE-2017-15573MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

  • CVE-2017-15571MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.

  • CVE-2017-15570MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.

  • CVE-2017-15569MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.

  • CVE-2017-15568MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.

  • CVE-2016-10515MedOct 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.

  • CVE-2015-8477MedMay 23, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.

  • CVE-2026-1836MedJun 12, 2026
    risk 0.34cvss epss 0.00

    The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

  • CVE-2017-16804MedNov 13, 2017
    risk 0.28cvss 4.3epss 0.02

    In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

  • CVE-2015-8537MedApr 12, 2016
    risk 0.28cvss 5.3epss 0.02

    app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.

  • CVE-2015-8346MedApr 12, 2016
    risk 0.28cvss 5.3epss 0.02

    app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

  • CVE-2025-4011LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated…

  • CVE-2015-8473MedApr 12, 2016
    risk 0.21cvss 4.3epss 0.02

    The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

  • CVE-2011-4929Oct 8, 2012
    risk 0.07cvss epss 0.46

    Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

  • CVE-2024-37663Jun 17, 2024
    risk 0.00cvss epss 0.00

    Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

  • CVE-2024-37664Jun 17, 2024
    risk 0.00cvss epss 0.00

    Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

  • CVE-2023-47259Nov 5, 2023
    risk 0.00cvss epss 0.00

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

  • CVE-2023-47258Nov 5, 2023
    risk 0.00cvss epss 0.00

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

  • CVE-2023-47260Nov 5, 2023
    risk 0.00cvss epss 0.00

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

  • CVE-2022-44031Dec 12, 2022
    risk 0.00cvss epss 0.00

    Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.

  • CVE-2022-44637Dec 12, 2022
    risk 0.00cvss epss 0.00

    Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.

  • CVE-2022-44030Dec 6, 2022
    risk 0.00cvss epss 0.01

    Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

  • CVE-2021-42326Oct 12, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

  • CVE-2021-37156Aug 5, 2021
    risk 0.00cvss epss 0.01

    Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

  • CVE-2021-31863Apr 28, 2021
    risk 0.00cvss epss 0.02

    Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.

  • CVE-2021-31864Apr 28, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

  • CVE-2021-31865Apr 28, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

  • CVE-2021-31866Apr 28, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

  • CVE-2021-30163Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

  • CVE-2020-36306Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

  • CVE-2020-36307Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

  • CVE-2020-36308Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

  • CVE-2019-25026Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

  • CVE-2021-30164Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

  • CVE-2021-29274Mar 29, 2021
    risk 0.00cvss epss 0.01

    Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

  • CVE-2019-18890Nov 21, 2019
    risk 0.00cvss epss 0.04

    A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

  • CVE-2019-17427Oct 10, 2019
    risk 0.00cvss epss 0.02

    In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

  • CVE-2019-15950Sep 16, 2019
    risk 0.00cvss epss 0.01

    The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.

  • CVE-2017-18026HigJan 10, 2018
    risk 0.00cvss 8.8epss 0.03

    Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name…

  • CVE-2013-4663Dec 28, 2014
    risk 0.00cvss epss 0.02

    git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists…

  • CVE-2014-1985Apr 11, 2014
    risk 0.00cvss epss 0.03

    Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back…

  • CVE-2011-4928Oct 8, 2012
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-4927Oct 8, 2012
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

Page 1 of 2