CVE Tools

Theforeman

48 CVEs tracked since 2013. Since Jul 2013, none of them reached CISA KEV.

Theforeman CVEs per month

Jul 2013 to Dec 2019. Point at a month, or focus the strip and use the arrow keys.
Theforeman CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-0720
2013-08null or fewer
2013-0920
2013-10null or fewer
2013-1110
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-0310
2014-0420
2014-0590
2014-0620
2014-0720
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-0310
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-0710
2015-0840
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-1210
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-0410
2016-0520
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-1030
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0730
2018-0830
2018-0930
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-1250

Products

The products that kept showing up in Theforeman's monthly top three, with their CVEs summed over those months.

  1. Foreman4019 months
  2. Katello64 months
  3. Hammer Cli11 month
  4. Kafo11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Theforeman.

  1. CVE-2026-5138Foreman: foreman: information disclosure via improper validation of nested request parameters4.3
  2. CVE-2026-5135Foreman: foreman: unauthorized modification of host configurations via broken access control6.5
  3. CVE-2026-5142Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass6.5
  4. CVE-2026-5136Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation8.8
  5. CVE-2026-13316Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config4.4
  6. CVE-2026-9073Foreman-mcp-server: mcp server: insecure sensitive http header sanitization6.2
  7. CVE-2026-12112Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse7.8
  8. CVE-2024-7700Foreman: command injection in "host init config" template via "install packages" field on foreman6.5
  9. CVE-2023-4886Foreman: world readable file containing secrets6.7
  10. CVE-2022-3874Os command injection via ct_command and fcct_command8.0
  11. CVE-2023-0462Arbitrary code execution through yaml global parameters8.0
  12. CVE-2023-0118Foreman: arbitrary code execution through templates9.1
  13. CVE-2021-20260A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulne...7.8
  14. CVE-2021-3590A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is ...8.8
  15. CVE-2020-10710A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges...4.4

The record

Peak rank
#19 in May 2014
Busiest month shown
May 2014, 9 CVEs
Months with a KEV entry
0 since Jul 2013
Monthly snapshots
19 since 2013
Theforeman's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store