Technology · PyPI
trac (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in trac (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2009-4405, was published on 23 December 2009.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest trac (PyPI) vulnerabilities
- CVE-2009-4405: PYSEC-2009-7 - Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly…lowCVSS 3.1EPSS 2.0%
- CVE-2008-5646: PYSEC-2008-6 - Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown…lowCVSS 3.1EPSS 1.2%
- CVE-2008-5647: PYSEC-2008-7 - Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct…lowCVSS 3.1EPSS 1.1%
- CVE-2008-2951: PYSEC-2008-4 - Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect…lowCVSS 3.1EPSS 1.8%
- CVE-2008-3328: PYSEC-2008-5 - Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to…lowCVSS 3.1EPSS 1.3%
- CVE-2007-1406: PYSEC-2007-3 - Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain…lowCVSS 3.1EPSS 1.3%
- CVE-2007-1405: PYSEC-2007-2 - Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before…lowCVSS 3.1EPSS 1.1%
- CVE-2006-5878: PYSEC-2006-3 - Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to…lowCVSS 3.1EPSS 2.1%
- CVE-2006-3695: PYSEC-2006-2 - Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with…lowCVSS 3.1EPSS 1.9%
- CVE-2005-4644: PYSEC-2005-1 - Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote…lowCVSS 3.1EPSS 1.5%
Most severe trac (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2006-5878: PYSEC-2006-3 - Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to…lowCVSS 3.1EPSS 2.1%
- CVE-2009-4405: PYSEC-2009-7 - Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly…lowCVSS 3.1EPSS 2.0%
- CVE-2006-3695: PYSEC-2006-2 - Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with…lowCVSS 3.1EPSS 1.9%
- CVE-2008-2951: PYSEC-2008-4 - Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect…lowCVSS 3.1EPSS 1.8%
- CVE-2005-4644: PYSEC-2005-1 - Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote…lowCVSS 3.1EPSS 1.5%
- CVE-2008-3328: PYSEC-2008-5 - Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to…lowCVSS 3.1EPSS 1.3%
- CVE-2007-1406: PYSEC-2007-3 - Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain…lowCVSS 3.1EPSS 1.3%
- CVE-2008-5646: PYSEC-2008-6 - Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown…lowCVSS 3.1EPSS 1.2%
- CVE-2007-1405: PYSEC-2007-2 - Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before…lowCVSS 3.1EPSS 1.1%
- CVE-2008-5647: PYSEC-2008-7 - Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct…lowCVSS 3.1EPSS 1.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/trac.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "trac (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/trac, 27 September 2026.