Vanderbilt / Redcap
41 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-55374 | REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. | MEDIUM | 5.3 | Jan 2, 2026 |
| CVE-2024-37396 | A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML… | MEDIUM | 5.4 | Jun 10, 2025 |
| CVE-2024-37395 | A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or… | MEDIUM | 5.4 | Jun 10, 2025 |
| CVE-2024-37394 | A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML… | MEDIUM | 5.4 | Jun 10, 2025 |
| CVE-2025-23113 | An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containin… | HIGH | 8.8 | Jan 10, 2025 |
| CVE-2025-23112 | An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Sur… | MEDIUM | 6.1 | Jan 10, 2025 |
| CVE-2025-23111 | An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacke… | MEDIUM | 6.1 | Jan 10, 2025 |
| CVE-2025-23110 | An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of… | MEDIUM | 6.1 | Jan 10, 2025 |
| CVE-2024-56377 | A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Titl… | MEDIUM | 5.4 | Jan 9, 2025 |
| CVE-2024-56376 | A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the me… | MEDIUM | 5.4 | Jan 9, 2025 |
| CVE-2024-56314 | A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the… | MEDIUM | 5.4 | Dec 22, 2024 |
| CVE-2024-56313 | A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into… | MEDIUM | 5.4 | Dec 22, 2024 |
| CVE-2024-56312 | A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts… | MEDIUM | 5.4 | Dec 22, 2024 |
| CVE-2024-56311 | REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker ca… | HIGH | 8.8 | Dec 22, 2024 |
| CVE-2024-56310 | REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit… | HIGH | 8.8 | Dec 22, 2024 |
| CVE-2024-45527 | REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also… | MEDIUM | 6.1 | Sep 2, 2024 |
| CVE-2023-38825 | SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in M… | CRITICAL | 9.8 | Mar 6, 2024 |
| CVE-2023-37798 | A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrar… | MEDIUM | 5.4 | Sep 7, 2023 |
| CVE-2023-37361 | REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization. | LOW | 2.7 | Jul 25, 2023 |
| CVE-2022-42715 | A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger ar… | MEDIUM | 6.1 | Oct 12, 2022 |
| CVE-2022-24127 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with… | MEDIUM | 5.4 | Jun 15, 2022 |
| CVE-2022-24004 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticated user to… | MEDIUM | 5.4 | Jun 15, 2022 |
| CVE-2021-42136 | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript… | CRITICAL | 9.0 | Apr 13, 2022 |
| CVE-2020-26713 | REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the r… | MEDIUM | 6.1 | Jan 12, 2021 |
| CVE-2020-26712 | REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information… | CRITICAL | 9.8 | Jan 12, 2021 |
Showing 1 to 25 of 41 CVEs