Redmine is a modestly deployed project-management and issue-tracking platform whose vulnerability footprint, though moderate in volume, sits among the more prominent in the application-security landscape due to the sensitive data project repositories often contain. The exposure concentrates in the core Redmine application and its Git hosting plugin, where vulnerabilities recur through web-application weakness classes including cross-site scripting, input validation flaws, and improper access controls that are characteristic of applications handling authentication, project metadata, and user collaboration. The recurring patterns reflect the complexity of a multi-tenant web platform that integrates version control, user roles, and permission models. Defenders should treat Redmine instances as requiring regular patching, particularly those exposed on shared infrastructure or integrated with external identity systems; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redmine over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4929HIGH Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors. | Oct 8, 2012 | 7.5 | 68 | NO | YES |
CVE-2021-30164CRITICAL Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API. | Apr 6, 2021 | 9.8 | 29 | NO | NO |
CVE-2017-18026HIGH Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to exec | Jan 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2011-1723MEDIUM Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_ | Apr 19, 2011 | 4.3 | 26 | NO | YES |
CVE-2017-15572HIGH In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password do | Oct 18, 2017 | 7.5 | 25 | NO | NO |
CVE-2022-44030HIGH Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may requir | Dec 6, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-30163HIGH Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values. | Apr 6, 2021 | 7.5 | 24 | NO | NO |
CVE-2017-15577HIGH Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information. | Oct 18, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-15576HIGH Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information. | Oct 18, 2017 | 7.5 | 24 | NO | NO |
CVE-2026-1836MEDIUM The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and | Jun 12, 2026 | 5.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redmine.
Media articles that mention a CVE ID that affects a product developed by Redmine — matched by CVE ID, not by vendor name.