Redcap

Vendor:

First CVE: Jun 17, 2013 · Active for 13 years

41
Total CVEs
More Total CVEs than 97% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Redcap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2013
13 years ago
Most Recent CVE
Jan 2, 2026
203 days ago

CVE Severity & Scoring

Redcap41 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (80.5%)
Unknown8 (19.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (78.0%)
High1 (2.4%)
Unknown8 (19.5%)
User Interaction
None7 (17.1%)
Unknown8 (19.5%)
Required26 (63.4%)
Privileges Required
Low18 (43.9%)
High2 (4.9%)
None13 (31.7%)
Unknown8 (19.5%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's
Apr 13, 20229.042NOYES
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted us
Jan 12, 20219.831NONO
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
Feb 8, 20188.828NONO
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.
Jun 17, 201310.028NONO
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious
Jul 11, 20194.827NOYES
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
Jul 18, 20178.826NONO
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The att
Aug 17, 20197.525NONO
Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Su
Jun 17, 201310.025NONO
An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing a list of alert con
Jan 10, 20258.824NONO
REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by lur
Dec 22, 20248.824NONO

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For Redcap

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.14.457.01.8%00
4.14.366.61.7%00
4.14.266.61.7%00
4.14.176.11.6%00
4.14.085.91.6%00
14.9.666.30.3%00
14.7.016.10.2%00
14.3.1315.30.2%00
12.0.1125.40.7%00
10.3.428.01.6%00
10.0.2028.01.6%00