CVEs affecting projects tracked on Release Alert, from NVD & OSV.
The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.