Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

foreman — Vulnerabilities & Security Advisories 26

All 26 CVE vulnerabilities found in foreman, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumerations associated with the Foreman product ecosystem. It aggregates security vulnerabilities identified within the infrastructure management software and its integrated components. The database compiles findings from various sources, providing a centralized view of security flaws that impact system integrity, confidentiality, and availability for users relying on this platform. The content gathered here spans a wide chronological range, capturing historical vulnerabilities from early releases up to recent patches. This comprehensive timeline allows security professionals to analyze long-term trends and the evolving threat landscape specific to Foreman. By consolidating data from multiple advisory sources, the page offers a holistic perspective on how weaknesses have been discovered, reported, and mitigated over time. Visitors to this resource can effectively track vendor advisories related to specific Foreman versions, enabling faster response to emerging threats. It also facilitates a deeper understanding of specific weakness classes, such as improper input validation or privilege escalation issues, within the context of this particular software. Furthermore, users can look up a product's vulnerability history to assess past security postures and identify recurring patterns in code quality or design flaws. This structured approach supports informed decision-making for system administrators and security auditors seeking to harden their deployments against known risks without needing to scour disparate security bulletins.

Vendor: Foreman

CVE IDTitleCVSSSeverityPublished
CVE-2025-9572 Foreman: satellite: graphql api permission bypass leads to information disclosure CWE-863 5.0 Medium2026-02-27
CVE-2025-10622 Foreman: os command injection via ct_location and fcct_location parameters CWE-78 8.0 High2025-11-05
CVE-2022-3874 Os command injection via ct_command and fcct_command CWE-78 8.0 High2023-09-22
CVE-2023-0462 Arbitrary code execution through yaml global parameters CWE-94 8.0 High2023-09-20
CVE-2021-20260 Foreman 安全漏洞 CWE-200 7.8 -2022-08-26
CVE-2021-3590 Foreman 安全漏洞 CWE-200 8.8 -2022-08-22
CVE-2021-3584 Foreman 操作系统命令注入漏洞 CWE-78 7.2 -2021-12-23
CVE-2021-20259 Foreman 信息泄露漏洞 CWE-200 7.8 -2021-06-07
CVE-2021-3469 Foreman 安全漏洞 CWE-863 6.3 -2021-06-03
CVE-2021-3494 Foreman 安全漏洞 CWE-319 5.9 -2021-04-26
CVE-2014-0091 Foreman 输入验证错误漏洞 5.3 -2019-12-11
CVE-2014-8183 Foreman访问控制错误漏洞 CWE-284 7.4 -2019-08-01
CVE-2019-3893 Foreman 信息泄露漏洞 CWE-732 6.5 -2019-04-09
CVE-2018-16861 Foreman 跨站脚本漏洞 CWE-79 4.8 -2018-12-07
CVE-2018-14664 Foreman 跨站脚本漏洞 CWE-79 5.4 -2018-10-12
CVE-2016-7078 Foreman 信息泄露漏洞 CWE-285 4.3 -2018-09-10
CVE-2016-7077 Foreman 信息泄露漏洞 CWE-285 4.3 -2018-09-10
CVE-2016-8639 Foreman 跨站脚本漏洞 CWE-79 5.4 -2018-08-01
CVE-2016-8634 Foreman 跨站脚本漏洞 CWE-79 5.4 -2018-08-01
CVE-2016-8613 Foreman 跨站脚本漏洞 CWE-79 6.1 -2018-07-31
CVE-2017-7535 Foreman 跨站脚本漏洞 CWE-79 5.4 -2018-07-26
CVE-2017-2672 Foreman 信息泄露漏洞 CWE-312 8.8 -2018-06-21
CVE-2018-1096 Foreman dashboard controller SQL注入漏洞 CWE-89 8.1 -2018-04-05
CVE-2018-1097 Foreman 信息泄露漏洞 CWE-200 8.8 -2018-04-04
CVE-2017-15100 Foreman 跨站脚本漏洞 CWE-79 6.1 -2017-11-27
CVE-2017-7505 Foreman 安全漏洞 CWE-863 8.1 -2017-05-26

All 26 known CVE vulnerabilities affecting foreman with full Chinese analysis, references, and POCs where available.