Foreman / Foreman
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-9572 | Foreman: satellite: graphql api permission bypass leads to information disclosure | MEDIUM | 6.5 | Feb 27, 2026 |
| CVE-2025-10622 | Foreman: os command injection via ct_location and fcct_location parameters | HIGH | 8.0 | Nov 5, 2025 |
| CVE-2014-0091 | Foreman: Improper input validation | MEDIUM | 5.3 | Dec 11, 2019 |
| CVE-2019-3893 | foreman: Recover of plaintext password or token for the compute resources | MEDIUM | 4.9 | Apr 9, 2019 |
| CVE-2018-16861 | foreman: stored XSS in success notification after entity creation | HIGH | 7.6 | Dec 7, 2018 |
| CVE-2016-7078 | foreman: Information leak through organizations and locations feature | MEDIUM | 4.3 | Sep 10, 2018 |
| CVE-2016-7077 | foreman: Foreman information leak through unauthorized multiple_checkboxes helper | MEDIUM | 4.3 | Sep 10, 2018 |
| CVE-2016-8639 | foreman: Stored XSS via organization/location with HTML in name | MEDIUM | 6.1 | Aug 1, 2018 |
| CVE-2016-8634 | foreman: Stored XSS in org/loc wizard | MEDIUM | 6.1 | Aug 1, 2018 |
| CVE-2016-8613 | foreman: Stored XSS vulnerability in remote execution plugin | MEDIUM | 6.4 | Jul 31, 2018 |
| CVE-2017-7535 | foreman: XSS in the manage organization page | MEDIUM | 6.1 | Jul 26, 2018 |
| CVE-2018-1096 | foreman: SQL injection due to improper handling of the widget id parameter | MEDIUM | 6.5 | Apr 5, 2018 |
| CVE-2018-1097 | foreman: Ovirt admin password exposed by foreman API | HIGH | 8.8 | Apr 4, 2018 |
| CVE-2017-15100 | foreman: Stored XSS in fact name or value | MEDIUM | 6.1 | Nov 27, 2017 |
| CVE-2017-7505 | foreman: Users with user management permission assigned to organization can manage user objects outside of the organization | HIGH | 8.8 | May 26, 2017 |
Showing 1 to 10 of 10 CVEs