Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Redmine

First CVE: Oct 8, 2008Active for: 18 yearsTotal CVEs: 52
31.1
VTI Score
Medium

Redmine is a modestly deployed project-management and issue-tracking platform whose vulnerability footprint, though moderate in volume, sits among the more prominent in the application-security landscape due to the sensitive data project repositories often contain. The exposure concentrates in the core Redmine application and its Git hosting plugin, where vulnerabilities recur through web-application weakness classes including cross-site scripting, input validation flaws, and improper access controls that are characteristic of applications handling authentication, project metadata, and user collaboration. The recurring patterns reflect the complexity of a multi-tenant web platform that integrates version control, user roles, and permission models. Defenders should treat Redmine instances as requiring regular patching, particularly those exposed on shared infrastructure or integrated with external identity systems; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Redmine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 8, 2008
17 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-4929HIGH
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.
Oct 8, 20127.568NOYES
CVE-2021-30164CRITICAL
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
Apr 6, 20219.829NONO
CVE-2017-18026HIGH
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to exec
Jan 10, 20188.827NONO
CVE-2011-1723MEDIUM
Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_
Apr 19, 20114.326NOYES
CVE-2017-15572HIGH
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password do
Oct 18, 20177.525NONO
CVE-2022-44030HIGH
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may requir
Dec 6, 20227.524NONO
CVE-2021-30163HIGH
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
Apr 6, 20217.524NONO
CVE-2017-15577HIGH
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
Oct 18, 20177.524NONO
CVE-2017-15576HIGH
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
Oct 18, 20177.524NONO
CVE-2026-1836MEDIUM
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and
Jun 12, 20265.323NONO
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
75%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.9%)
Network39 (75.0%)
Unknown12 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (76.9%)
High0 (0.0%)
Unknown12 (23.1%)
User Interaction
None20 (38.5%)
Unknown12 (23.1%)
Required19 (36.5%)
Privileges Required
Low4 (7.7%)
High0 (0.0%)
None36 (69.2%)
Unknown12 (23.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Redmine.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Redmine — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Redmine's Products

View all 4 CNAs →

Top CWEs