CVE-2025-4011
- EPSS 0.03%
- Published 28.04.2025 08:00:11
- Last modified 29.04.2025 13:52:10
A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scripting. The a...
CVE-2023-47260
- EPSS 0.35%
- Published 05.11.2023 04:15:10
- Last modified 21.11.2024 08:30:04
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
CVE-2023-47259
- EPSS 0.42%
- Published 05.11.2023 04:15:10
- Last modified 21.11.2024 08:30:04
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
CVE-2023-47258
- EPSS 0.42%
- Published 05.11.2023 04:15:10
- Last modified 21.11.2024 08:30:04
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
CVE-2022-44637
- EPSS 0.55%
- Published 12.12.2022 03:15:09
- Last modified 23.04.2025 14:15:24
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
CVE-2022-44031
- EPSS 0.55%
- Published 12.12.2022 03:15:09
- Last modified 22.04.2025 21:15:43
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
CVE-2022-44030
- EPSS 0.26%
- Published 06.12.2022 23:15:10
- Last modified 23.04.2025 17:16:21
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
CVE-2021-42326
- EPSS 0.51%
- Published 12.10.2021 19:15:08
- Last modified 21.11.2024 06:27:36
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
CVE-2021-37156
- EPSS 0.25%
- Published 05.08.2021 21:15:12
- Last modified 21.11.2024 06:14:44
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
CVE-2021-31863
- EPSS 0.79%
- Published 28.04.2021 07:15:07
- Last modified 21.11.2024 06:06:22
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.