Skip to main content

Vendor/product archive

dradisframework / dradis CVEs

Beta · best-effort

6 CVEs tagged to dradisframework / dradis0 Critical, 1 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2023-50458

Published Jul 10, 2025

In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-50786

Published Jul 5, 2025

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized a…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30028

Published Jun 24, 2022

Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19946

Published Mar 16, 2020

The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5925

Published Mar 12, 2019

Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authentic…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1