Foreman
Foreman · 10 CVEs
Foreman: satellite: graphql api permission bypass leads to information disclosure
Feb 27, 2026
Foreman: os command injection via ct_location and fcct_location parameters
Nov 5, 2025
Foreman: Improper input validation
Dec 11, 2019
foreman: Recover of plaintext password or token for the compute resources
Apr 9, 2019
foreman: stored XSS in success notification after entity creation
Dec 7, 2018
foreman: Information leak through organizations and locations feature
Sep 10, 2018
foreman: Foreman information leak through unauthorized multiple_checkboxes helper
Sep 10, 2018
foreman: Stored XSS via organization/location with HTML in name
Aug 1, 2018
foreman: Stored XSS in org/loc wizard
Aug 1, 2018
foreman: Stored XSS vulnerability in remote execution plugin
Jul 31, 2018
foreman: XSS in the manage organization page
Jul 26, 2018
foreman: SQL injection due to improper handling of the widget id parameter
Apr 5, 2018
foreman: Ovirt admin password exposed by foreman API
Apr 4, 2018
foreman: Stored XSS in fact name or value
Nov 27, 2017
foreman: Users with user management permission assigned to organization can manage user objects outside of the organiza…
May 26, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-9572 | Foreman: satellite: graphql api permission bypass leads to information disclosure | MEDIUM | 0.35% | Feb 27, 2026 |
| CVE-2025-10622 | Foreman: os command injection via ct_location and fcct_location parameters | HIGH | 0.58% | Nov 5, 2025 |
| CVE-2014-0091 | Foreman: Improper input validation | MEDIUM | 1.55% | Dec 11, 2019 |
| CVE-2019-3893 | foreman: Recover of plaintext password or token for the compute resources | MEDIUM | 1.83% | Apr 9, 2019 |
| CVE-2018-16861 | foreman: stored XSS in success notification after entity creation | HIGH | 0.88% | Dec 7, 2018 |
| CVE-2016-7078 | foreman: Information leak through organizations and locations feature | MEDIUM | 1.36% | Sep 10, 2018 |
| CVE-2016-7077 | foreman: Foreman information leak through unauthorized multiple_checkboxes helper | MEDIUM | 1.37% | Sep 10, 2018 |
| CVE-2016-8639 | foreman: Stored XSS via organization/location with HTML in name | MEDIUM | 1.16% | Aug 1, 2018 |
| CVE-2016-8634 | foreman: Stored XSS in org/loc wizard | MEDIUM | 1.09% | Aug 1, 2018 |
| CVE-2016-8613 | foreman: Stored XSS vulnerability in remote execution plugin | MEDIUM | 2.40% | Jul 31, 2018 |
| CVE-2017-7535 | foreman: XSS in the manage organization page | MEDIUM | 1.49% | Jul 26, 2018 |
| CVE-2018-1096 | foreman: SQL injection due to improper handling of the widget id parameter | MEDIUM | 1.33% | Apr 5, 2018 |
| CVE-2018-1097 | foreman: Ovirt admin password exposed by foreman API | HIGH | 1.74% | Apr 4, 2018 |
| CVE-2017-15100 | foreman: Stored XSS in fact name or value | MEDIUM | 1.10% | Nov 27, 2017 |
| CVE-2017-7505 | foreman: Users with user management permission assigned to organization can manage user objects outside of the organization | HIGH | 1.59% | May 26, 2017 |
Showing 1 to 10 of 10 CVEs