Edgewall Software

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-0394

    PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.

    Last Modified: Apr 11, 2025
    Published: Feb 10, 2010

    CVE-2008-3328

    trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)

    Last Modified: Apr 23, 2026
    Published: Jun 13, 2008

    CVE-2007-1405

    Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Last Modified: Apr 23, 2026
    Published: Mar 10, 2007

    CVE-2007-1406

    Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

    Last Modified: Apr 23, 2026
    Published: Mar 10, 2007

    CVE-2006-5878

    Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.

    Last Modified: Apr 23, 2026
    Published: Nov 14, 2006
    Items Per Page