VendorsEnaleantuleapall versions
Vulnerabilities

Enalean Tuleap

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

68CVEs
CVE-2025-52899
Tuleap vulnerable to user enumeration via the lost password form
Published 2025-07-29 · Analyzed
5.3EPSS 0.003
CVE-2024-47766
Permissions are incorrectly verified for project administrators in the cross tracker search widget
Published 2024-10-14 · Analyzed
4.9EPSS 0.005
CVE-2023-39521
Tuleap vulnerable to Cross-site Scripting on the success message of a kanban deletion
Published 2023-08-24 · Modified
4.8EPSS 0.006
CVE-2023-32072
Tuleap vulnerable toXSS via the triggered job URL of a Jenkins job
Published 2023-05-29 · Modified
4.8EPSS 0.005
CVE-2024-46980
Tuleap vulnerable to XSS in the HTML mail content of the cross reference field
Published 2024-10-14 · Analyzed
4.8EPSS 0.004
CVE-2024-39902
Tuleap's recursive permissions to document manager folder are not properly applied
Published 2024-07-22 · Analyzed
4.8EPSS 0.003
CVE-2025-30203
Tuleap allows XSS via the content of RSS feeds in the RSS widgets
Published 2025-03-31 · Analyzed
4.8EPSS 0.003
CVE-2025-27099
Tuleap allows XSS via the tracker names used in the semantic timeframe deletion message
Published 2025-03-03 · Analyzed
4.8EPSS 0.003
CVE-2025-27401
In Tuleap, deleting a report can delete criteria filters in other reports
Published 2025-03-04 · Analyzed
4.6EPSS 0.003
CVE-2025-29766
Tuleap has missing CSRF protections on artifact submission & edition from the tracker view
Published 2025-03-31 · Analyzed
4.6EPSS 0.002
CVE-2025-29929
Tuleap is missing CSRF protection on tracker hierarchy administration
Published 2025-03-31 · Analyzed
4.6EPSS 0.002
CVE-2025-48991
Tuleap missing CSRF protection on tracker canned responses administration
Published 2025-06-25 · Analyzed
4.6EPSS 0.002
CVE-2025-50179
Tuleap missing CSRF protection on tracker reports manipulation
Published 2025-06-25 · Analyzed
4.6EPSS 0.002
CVE-2025-27402
Tuleap is missing CSRF protections on tracker fields administrative operations
Published 2025-03-04 · Analyzed
4.6EPSS 0.002
CVE-2025-65962
Tuleap has missing CSRF protections its in tracker field dependencies
Published 2025-12-08 · Analyzed
4.6EPSS 0.002
CVE-2026-24007
Tuleap is missing CSRF protection in the Overview inconsistent items
Published 2026-02-02 · Analyzed
4.6EPSS 0.001
CVE-2025-64498
Tuleap has a Cross-Site Request Forgery (CSRF) vulnerability
Published 2025-12-08 · Analyzed
4.6EPSS 0.001
CVE-2025-64760
Tuleap has missing CSRF protections in its tracker trigger management system
Published 2025-12-08 · Analyzed
4.6EPSS 0.001
CVE-2022-31032
Resources of private projects can be exposed in Tuleap
Published 2022-06-29 · Modified
4.3EPSS 0.010
CVE-2022-24896
Tracker report renderer and chart widgets leak information in Tuleap
Published 2022-06-06 · Modified
4.3EPSS 0.008
CVE-2022-46160
Tuleap dashboards vulnerable to Incorrect Authorization
Published 2022-12-13 · Modified
4.3EPSS 0.005
CVE-2022-23473
Tuleap MediaWiki standalone "readers" can also edit pages
Published 2022-12-13 · Modified
4.3EPSS 0.005
CVE-2024-47767
Tuleap lists trackers in the quick add actions of the backlog without any permissions check
Published 2024-10-14 · Analyzed
4.3EPSS 0.004
CVE-2024-37167
Tuleap has improper permissions of the backlog items
Published 2024-06-25 · Analyzed
4.3EPSS 0.004
CVE-2025-22129
Initial effort field does not respect field permissions in the Taskboard REST card representation in Tuleap
Published 2025-02-03 · Analyzed
4.3EPSS 0.003
CVE-2025-30155
Tuleap does not enforce read permissions on parent trackers in the REST API
Published 2025-03-31 · Analyzed
4.3EPSS 0.003
CVE-2025-53902
Tuleap exposes artifacts to a mentioned user via email notifications
Published 2025-07-29 · Analyzed
4.3EPSS 0.003
CVE-2014-7177
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.
Published 2014-10-31 · Modified
4.01 PoCEPSS 0.033
← Prev2 / 2