Foreman

Vendor:

First CVE: Jul 31, 2013 · Active for 12 years

77
Total CVEs
More Total CVEs than 99% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Foreman over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

CVE Severity & Scoring

Foreman77 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local7 (9.1%)
Network44 (57.1%)
Unknown26 (33.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (57.1%)
High7 (9.1%)
Unknown26 (33.8%)
User Interaction
None37 (48.1%)
Unknown26 (33.8%)
Required14 (18.2%)
Privileges Required
Low29 (37.7%)
High10 (13.0%)
None12 (15.6%)
Unknown26 (33.8%)

Top CVEs

Signals from CVEs in this product scope (77 CVEs).

77 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to
Jul 31, 20136.045NOYES
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privil
Jul 31, 20136.043NOYES
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user wi
Jul 1, 20268.839NONO
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_bo
Jun 20, 20147.538NOYES
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an
Jun 23, 20267.833NONO
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machi
Sep 21, 20189.833NONO
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a dif
Jul 1, 20266.532NONO
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other o
Jul 1, 20266.532NONO
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora
Sep 22, 20239.129NONO
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs sessio
Jun 23, 20266.228NONO

Exploit Exposure

Signals from CVEs in this product scope (77 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
3.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (77 CVEs).

Media Mentions

Signals from CVEs in this product scope (77 CVEs).

Top CNAs Publishing CVEs For Foreman

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.017.23.9%00
1.9.327.51.3%00
1.9.227.51.3%00
1.9.127.51.3%00
1.9.047.71.4%00
1.8.427.51.3%00
1.8.337.71.4%00
1.8.237.71.4%00
1.8.137.71.4%00
1.8.038.21.5%00
1.7.537.71.4%00
1.7.437.71.4%00
1.7.337.71.4%00
1.7.237.71.4%00
1.7.137.71.4%00
1.7.038.11.5%00
1.6.318.81.6%00
1.6.138.11.6%00
1.6.038.31.6%00
1.5.328.41.6%00