{"schema_version":1,"title":"trac (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in trac (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2009-4405, was published on 23 December 2009.","url":"https://junglewise.ai/threats/technologies/trac","json_url":"https://junglewise.ai/threats/technologies/trac.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/trac","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":10,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2009-4405","cvss":3.1,"epss":0.0197,"slug":"cve-2009-4405-trac-is-vulnerable-to-improper-policy-checks-and-missing-raw-role","title":"PYSEC-2009-7 - Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) \"policy checks in","severity":"low","exploited":false,"published_at":"2009-12-23T21:30:00+00:00","url":"https://junglewise.ai/threats/cve-2009-4405-trac-is-vulnerable-to-improper-policy-checks-and-missing-raw-role"},{"cve":"CVE-2008-5646","cvss":3.1,"epss":0.0123,"slug":"cve-2008-5646-trac-vulnerable-to-denial-of-service","title":"PYSEC-2008-6 - Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown attack vectors related to \"certain","severity":"low","exploited":false,"published_at":"2008-12-17T18:30:00+00:00","url":"https://junglewise.ai/threats/cve-2008-5646-trac-vulnerable-to-denial-of-service"},{"cve":"CVE-2008-5647","cvss":3.1,"epss":0.0107,"slug":"cve-2008-5647-trac-has-vulnerability-in-html-sanitizer-filter","title":"PYSEC-2008-7 - Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct phishing attacks via unknown attack","severity":"low","exploited":false,"published_at":"2008-12-17T18:30:00+00:00","url":"https://junglewise.ai/threats/cve-2008-5647-trac-has-vulnerability-in-html-sanitizer-filter"},{"cve":"CVE-2008-2951","cvss":3.1,"epss":0.0183,"slug":"cve-2008-2951-trac-open-redirect-vulnerability","title":"PYSEC-2008-4 - Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and","severity":"low","exploited":false,"published_at":"2008-07-27T22:41:00+00:00","url":"https://junglewise.ai/threats/cve-2008-2951-trac-open-redirect-vulnerability"},{"cve":"CVE-2008-3328","cvss":3.1,"epss":0.0134,"slug":"cve-2008-3328-trac-cross-site-scripting-xss-vulnerability","title":"PYSEC-2008-5 - Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or","severity":"low","exploited":false,"published_at":"2008-07-27T22:41:00+00:00","url":"https://junglewise.ai/threats/cve-2008-3328-trac-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2007-1406","cvss":3.1,"epss":0.0134,"slug":"cve-2007-1406-trac-missing-content-disposition-http-header","title":"PYSEC-2007-3 - Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain \"unsafe\" situations, which has unkn","severity":"low","exploited":false,"published_at":"2007-03-10T22:19:00+00:00","url":"https://junglewise.ai/threats/cve-2007-1406-trac-missing-content-disposition-http-header"},{"cve":"CVE-2007-1405","cvss":3.1,"epss":0.0109,"slug":"cve-2007-1405-trac-cross-site-scripting-xss-vulnerability","title":"PYSEC-2007-2 - Cross-site scripting (XSS) vulnerability in the \"download wiki page as text\" feature in Trac before 0.10.3.1, when Microsoft Internet Explor","severity":"low","exploited":false,"published_at":"2007-03-10T22:19:00+00:00","url":"https://junglewise.ai/threats/cve-2007-1405-trac-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2006-5878","cvss":3.1,"epss":0.0214,"slug":"cve-2006-5878-edgewall-trac-cross-site-request-forgery","title":"PYSEC-2006-3 - Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as","severity":"low","exploited":false,"published_at":"2006-11-14T19:07:00+00:00","url":"https://junglewise.ai/threats/cve-2006-5878-edgewall-trac-cross-site-request-forgery"},{"cve":"CVE-2006-3695","cvss":3.1,"epss":0.019,"slug":"cve-2006-3695-trac-restructuredtext-breach-of-privacy-and-denial-of-service","title":"PYSEC-2006-2 - Trac before 0.9.6 does not disable the \"raw\" or \"include\" commands when providing untrusted users with restructured text (reStructuredText)","severity":"low","exploited":false,"published_at":"2006-07-21T14:03:00+00:00","url":"https://junglewise.ai/threats/cve-2006-3695-trac-restructuredtext-breach-of-privacy-and-denial-of-service"},{"cve":"CVE-2005-4644","cvss":3.1,"epss":0.0152,"slug":"cve-2005-4644-trac-html-wikiprocessor-cross-site-scripting-xss-vulnerability","title":"PYSEC-2005-1 - Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web sc","severity":"low","exploited":false,"published_at":"2005-12-31T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-2005-4644-trac-html-wikiprocessor-cross-site-scripting-xss-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"trac (PyPI)","slug":"trac","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/trac"},"most_severe":[{"cve":"CVE-2006-5878","cvss":3.1,"epss":0.0214,"slug":"cve-2006-5878-edgewall-trac-cross-site-request-forgery","title":"PYSEC-2006-3 - Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as","severity":"low","exploited":false,"published_at":"2006-11-14T19:07:00+00:00","url":"https://junglewise.ai/threats/cve-2006-5878-edgewall-trac-cross-site-request-forgery"},{"cve":"CVE-2009-4405","cvss":3.1,"epss":0.0197,"slug":"cve-2009-4405-trac-is-vulnerable-to-improper-policy-checks-and-missing-raw-role","title":"PYSEC-2009-7 - Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) \"policy checks in","severity":"low","exploited":false,"published_at":"2009-12-23T21:30:00+00:00","url":"https://junglewise.ai/threats/cve-2009-4405-trac-is-vulnerable-to-improper-policy-checks-and-missing-raw-role"},{"cve":"CVE-2006-3695","cvss":3.1,"epss":0.019,"slug":"cve-2006-3695-trac-restructuredtext-breach-of-privacy-and-denial-of-service","title":"PYSEC-2006-2 - Trac before 0.9.6 does not disable the \"raw\" or \"include\" commands when providing untrusted users with restructured text (reStructuredText)","severity":"low","exploited":false,"published_at":"2006-07-21T14:03:00+00:00","url":"https://junglewise.ai/threats/cve-2006-3695-trac-restructuredtext-breach-of-privacy-and-denial-of-service"},{"cve":"CVE-2008-2951","cvss":3.1,"epss":0.0183,"slug":"cve-2008-2951-trac-open-redirect-vulnerability","title":"PYSEC-2008-4 - Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and","severity":"low","exploited":false,"published_at":"2008-07-27T22:41:00+00:00","url":"https://junglewise.ai/threats/cve-2008-2951-trac-open-redirect-vulnerability"},{"cve":"CVE-2005-4644","cvss":3.1,"epss":0.0152,"slug":"cve-2005-4644-trac-html-wikiprocessor-cross-site-scripting-xss-vulnerability","title":"PYSEC-2005-1 - Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web sc","severity":"low","exploited":false,"published_at":"2005-12-31T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-2005-4644-trac-html-wikiprocessor-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2008-3328","cvss":3.1,"epss":0.0134,"slug":"cve-2008-3328-trac-cross-site-scripting-xss-vulnerability","title":"PYSEC-2008-5 - Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or","severity":"low","exploited":false,"published_at":"2008-07-27T22:41:00+00:00","url":"https://junglewise.ai/threats/cve-2008-3328-trac-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2007-1406","cvss":3.1,"epss":0.0134,"slug":"cve-2007-1406-trac-missing-content-disposition-http-header","title":"PYSEC-2007-3 - Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain \"unsafe\" situations, which has unkn","severity":"low","exploited":false,"published_at":"2007-03-10T22:19:00+00:00","url":"https://junglewise.ai/threats/cve-2007-1406-trac-missing-content-disposition-http-header"},{"cve":"CVE-2008-5646","cvss":3.1,"epss":0.0123,"slug":"cve-2008-5646-trac-vulnerable-to-denial-of-service","title":"PYSEC-2008-6 - Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown attack vectors related to \"certain","severity":"low","exploited":false,"published_at":"2008-12-17T18:30:00+00:00","url":"https://junglewise.ai/threats/cve-2008-5646-trac-vulnerable-to-denial-of-service"},{"cve":"CVE-2007-1405","cvss":3.1,"epss":0.0109,"slug":"cve-2007-1405-trac-cross-site-scripting-xss-vulnerability","title":"PYSEC-2007-2 - Cross-site scripting (XSS) vulnerability in the \"download wiki page as text\" feature in Trac before 0.10.3.1, when Microsoft Internet Explor","severity":"low","exploited":false,"published_at":"2007-03-10T22:19:00+00:00","url":"https://junglewise.ai/threats/cve-2007-1405-trac-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2008-5647","cvss":3.1,"epss":0.0107,"slug":"cve-2008-5647-trac-has-vulnerability-in-html-sanitizer-filter","title":"PYSEC-2008-7 - Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct phishing attacks via unknown attack","severity":"low","exploited":false,"published_at":"2008-12-17T18:30:00+00:00","url":"https://junglewise.ai/threats/cve-2008-5647-trac-has-vulnerability-in-html-sanitizer-filter"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}