redmine CVE Vulnerabilities & Metrics

Focus on redmine vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About redmine Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with redmine. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total redmine CVEs: 39
Earliest CVE date: 08 Oct 2008, 02:00 UTC
Latest CVE date: 05 Nov 2023, 04:15 UTC

Latest CVE reference: CVE-2023-47260

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical redmine CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.38

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 41
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS redmine CVEs

These are the five CVEs with the highest CVSS scores for redmine, sorted by severity first and recency.

All CVEs for redmine

CVE-2023-47260 redmine vulnerability CVSS: 0 05 Nov 2023, 04:15 UTC

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

CVE-2023-47259 redmine vulnerability CVSS: 0 05 Nov 2023, 04:15 UTC

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

CVE-2023-47258 redmine vulnerability CVSS: 0 05 Nov 2023, 04:15 UTC

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

CVE-2022-44637 redmine vulnerability CVSS: 0 12 Dec 2022, 03:15 UTC

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.

CVE-2022-44031 redmine vulnerability CVSS: 0 12 Dec 2022, 03:15 UTC

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.

CVE-2022-44030 redmine vulnerability CVSS: 0 06 Dec 2022, 23:15 UTC

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

CVE-2021-42326 redmine vulnerability CVSS: 5.0 12 Oct 2021, 19:15 UTC

Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

CVE-2021-37156 redmine vulnerability CVSS: 5.0 05 Aug 2021, 21:15 UTC

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

CVE-2021-31866 redmine vulnerability CVSS: 5.0 28 Apr 2021, 07:15 UTC

Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

CVE-2021-31865 redmine vulnerability CVSS: 5.0 28 Apr 2021, 07:15 UTC

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

CVE-2021-31864 redmine vulnerability CVSS: 5.0 28 Apr 2021, 07:15 UTC

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

CVE-2021-31863 redmine vulnerability CVSS: 5.0 28 Apr 2021, 07:15 UTC

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.

CVE-2021-30164 redmine vulnerability CVSS: 7.5 06 Apr 2021, 08:15 UTC

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

CVE-2021-30163 redmine vulnerability CVSS: 5.0 06 Apr 2021, 08:15 UTC

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

CVE-2020-36308 redmine vulnerability CVSS: 5.0 06 Apr 2021, 08:15 UTC

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

CVE-2020-36307 redmine vulnerability CVSS: 4.3 06 Apr 2021, 08:15 UTC

Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

CVE-2020-36306 redmine vulnerability CVSS: 4.3 06 Apr 2021, 08:15 UTC

Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

CVE-2019-25026 redmine vulnerability CVSS: 5.0 06 Apr 2021, 08:15 UTC

Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

CVE-2021-29274 redmine vulnerability CVSS: 4.3 29 Mar 2021, 04:15 UTC

Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

CVE-2019-18890 redmine vulnerability CVSS: 4.0 21 Nov 2019, 18:15 UTC

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

CVE-2019-17427 redmine vulnerability CVSS: 4.3 10 Oct 2019, 02:05 UTC

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

CVE-2017-18026 redmine vulnerability CVSS: 6.8 10 Jan 2018, 09:29 UTC

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.

CVE-2017-16804 redmine vulnerability CVSS: 4.0 13 Nov 2017, 20:29 UTC

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

CVE-2017-15577 redmine vulnerability CVSS: 5.0 18 Oct 2017, 02:29 UTC

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

CVE-2017-15576 redmine vulnerability CVSS: 5.0 18 Oct 2017, 02:29 UTC

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

CVE-2017-15575 redmine vulnerability CVSS: 7.5 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.

CVE-2017-15574 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

CVE-2017-15573 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

CVE-2017-15572 redmine vulnerability CVSS: 5.0 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.

CVE-2017-15571 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.

CVE-2017-15570 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.

CVE-2017-15569 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.

CVE-2017-15568 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.

CVE-2016-10515 redmine vulnerability CVSS: 4.3 18 Oct 2017, 02:29 UTC

In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.

CVE-2015-8477 redmine vulnerability CVSS: 4.3 23 May 2017, 04:29 UTC

Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.

CVE-2015-8537 redmine vulnerability CVSS: 5.0 12 Apr 2016, 14:59 UTC

app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.

CVE-2015-8474 redmine vulnerability CVSS: 5.8 12 Apr 2016, 14:59 UTC

Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.

CVE-2015-8473 redmine vulnerability CVSS: 4.0 12 Apr 2016, 14:59 UTC

The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

CVE-2015-8346 redmine vulnerability CVSS: 5.0 12 Apr 2016, 14:59 UTC

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

CVE-2013-4663 redmine vulnerability CVSS: 7.5 28 Dec 2014, 00:59 UTC

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.

CVE-2014-1985 redmine vulnerability CVSS: 5.8 11 Apr 2014, 14:55 UTC

Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (back_url parameter).

CVE-2011-4929 redmine vulnerability CVSS: 7.5 08 Oct 2012, 18:55 UTC

Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

CVE-2011-4928 redmine vulnerability CVSS: 4.3 08 Oct 2012, 18:55 UTC

Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-4927 redmine vulnerability CVSS: 4.0 08 Oct 2012, 18:55 UTC

Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2012-2054 redmine vulnerability CVSS: 5.0 05 Apr 2012, 14:55 UTC

Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327.

CVE-2012-0327 redmine vulnerability CVSS: 4.3 05 Apr 2012, 14:55 UTC

Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1723 redmine vulnerability CVSS: 4.3 19 Apr 2011, 19:55 UTC

Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

CVE-2009-4459 redmine vulnerability CVSS: 4.3 30 Dec 2009, 20:00 UTC

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

CVE-2009-4079 redmine vulnerability CVSS: 6.8 25 Nov 2009, 22:00 UTC

Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for requests that delete a ticket via unspecified vectors.

CVE-2009-4078 redmine vulnerability CVSS: 4.3 25 Nov 2009, 22:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2008-4481 redmine vulnerability CVSS: 4.3 08 Oct 2008, 02:00 UTC

Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.