Where
-Infinity
0

Vendor Risk Score

See how edgewall compares to other vendors in security performance

View Risk Score →
Severity
9.8
Code Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

First published (updated )
Severity
6.1
Input Validation
AV:N/AC:M/Au:N/C:N/I:P/A:P

Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.

First published (updated )
Severity
7.5
SQL Injection
AV:N/AC:L/Au:N/C:P/I:P/A:P

Description of problem: The latest upstream version is 0.11.6 (released yesterday). The current Fedora 12 (and rawhide version) is 0.11.4.

Version-Release number of selected component (if applicable): trac-0.11.4-2.fc12.src.rpm

Expected results: To have trac 0.11.6 available for F-12 and rawhide.

Additional info:

Release notes from versions 0.11.5 and 0.11.6: ---------- http://trac.edgewall.org/browser/tags/trac-0.11.5/RELEASE ---------- Changes in 0.11.5

Implemented pre-upgrade backup support for PostgreSQL and MySQL (#2304) Fixed PostgreSQL upgrade issue (#8378) More robust diff parsing (#2672) Avoid intermittent hangs by not calling aprterminate explicitly (#7785) Fixed display of merge properties for scoped repositories #7715. ---------- http://trac.edgewall.org/browser/tags/trac-0.11.6/RELEASE ---------- Changes in 0.11.6

Fixed the policy checks in report results when using alternate formats. Added a check for the "raw" role that is missing in docutils < 0.6. Re-enabled connection pooling with SQLite (#3446). Added caching of configuration options (#8510). Fixed the "database is locked" issue with SQLite (#3446, #8468). Deprecated SQLite 2.x support (#8625). Fixed hanlding of times in timezones with DST (#8240). Avoid corruption of trac.ini during write (#8623). Improved support for revision ranges in the revision log view (#8349) ----------

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
SQL Injection
AV:N/AC:L/Au:N/C:P/I:P/A:P

SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203