r
redmine
Security Risk Profile
43
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 68 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 8, 2008 to present
68
Total CVEs
14
Critical+High
0
Exploited
7
Unpatched
Threat Assessment
Avg CVSS
6.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
43/100
medium
Severity Distribution
Critical
1High
13Medium
40Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
24
2
Infoleak
5
3
Input Validation
2
4
Code Injection
1
5
Path Traversal
1
Most Affected Products
1. Redmine Redmine441
2. Debian Debian Linux29
3. debian/redmine14
4. Redmine DMSF Plugin1
5. Redmine Redmine Git Hosting Plugin1
Recent Vulnerabilities
See more →EOL-redmine-7.0
unknown
Jun 30, 2026
CVE-2026-1836
CVSS 5.3medium
Stored credentials in Redmine
Jun 12, 2026🔧 No Patch
EOL-redmine-6.1
unknown
Sep 21, 2025
CVE-2025-4011
CVSS 5.1EPSS 0%medium
Redmine Custom Query cross site scripting
Apr 28, 2025🔧 No Patch
EOL-redmine-6.0
unknown
Nov 10, 2024
latest-version-redmine-6.0
unknown
Nov 10, 2024
CVE-2024-36267
CVSS 8.1high
May 30, 2024🔧 No Patch
CVE-2023-47259
CVSS 6.1medium
Nov 5, 2023🔧 No Patch
CVE-2023-47260
CVSS 6.1medium
Nov 5, 2023🔧 No Patch
CVE-2023-47258
CVSS 6.1medium
Nov 5, 2023🔧 No Patch
Monitor redmine in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.