VendorsEnaleantuleapany version
Vulnerabilities

Enalean Tuleap any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

66CVEs
CVE-2018-7538
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.
Published 2018-03-12 · Modified
9.81 PoCEPSS 0.042
CVE-2018-17298
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
Published 2018-09-21 · Modified
9.8EPSS 0.018
CVE-2014-7178
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
Published 2014-11-28 · Modified
9.31 PoCEPSS 0.051
CVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax="c;id"' line to execute the id command.
Published 2017-04-29 · Modified
9.01 PoCEPSS 0.161
CVE-2017-7411
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject arbitrary PHP objects into the application scope, allowing an attacker to perform a variety of attacks (including but not limited to Remote Code Execution).
Published 2017-10-30 · Modified
8.81 PoCEPSS 0.666
CVE-2021-43806
SQL injection in Tuleap
Published 2021-12-15 · Modified
8.8EPSS 0.015
CVE-2021-41148
The update of the CI job targeted by a widget is vulnerable to blind SQL injections
Published 2021-10-15 · Modified
8.8EPSS 0.015
CVE-2021-41155
SQL injection in CVS revisions browser
Published 2021-10-18 · Modified
8.8EPSS 0.015
CVE-2021-41154
SQL injection in the "SVN core" commits browser
Published 2021-10-18 · Modified
8.8EPSS 0.015
CVE-2024-30246
Tuleap deleting or moving an artifact can delete values from unrelated artifacts
Published 2024-03-29 · Analyzed
7.6EPSS 0.006
CVE-2021-41147
SQL injection in the planning edition panel
Published 2021-10-15 · Modified
7.2EPSS 0.019
CVE-2021-41276
Indirect LDAP injection in Tuleap
Published 2021-12-15 · Modified
7.2EPSS 0.015
CVE-2022-31058
SQL injection via the field name of a tracker in Tuleap
Published 2022-06-29 · Modified
7.2EPSS 0.015
CVE-2021-43782
Indirect LDAP injection in Tuleap
Published 2021-12-15 · Modified
7.2EPSS 0.014
CVE-2023-35938
User access not updated with privilege change in Tuleap
Published 2023-06-29 · Modified
7.2EPSS 0.006
CVE-2014-7176
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.
Published 2014-11-04 · Modified
6.52 PoCEPSS 0.022
CVE-2022-31063
Cross site scripting via the title of a document in Tuleap
Published 2022-06-29 · Modified
6.5EPSS 0.007
CVE-2023-38508
Tuleap allows preview of a linked artifact with a type does not respect permissions
Published 2023-08-24 · Modified
6.5EPSS 0.007
CVE-2024-23344
Tuleap's content of artifacts might be readable by unauthorized users
Published 2024-02-06 · Modified
6.5EPSS 0.005
CVE-2024-25130
Tuleap's mass update clears the permissions on artifact field
Published 2024-02-22 · Analyzed
6.5EPSS 0.005
CVE-2025-27150
Tuleap dumps the Redis password into the generated troubleshooting archives
Published 2025-03-04 · Analyzed
6.5EPSS 0.004
CVE-2025-64497
Tuleap exposes releases for all projects to File Release System project administrators
Published 2025-12-08 · Analyzed
6.5EPSS 0.003
CVE-2023-23938
Cross-site Scripting (XSS) through the name of a color of select box values in tuleap
Published 2023-04-20 · Modified
5.9EPSS 0.005
CVE-2024-46988
Tuleap does not properly check permissions for email notifications in trackers
Published 2024-10-14 · Analyzed
5.7EPSS 0.004
CVE-2021-41142
XSS via the name of a deleted attachment
Published 2021-10-14 · Modified
5.4EPSS 0.007
CVE-2022-39233
Tuleap subject to Missing Authorization allowing for branch prefix modification
Published 2022-10-19 · Modified
5.4EPSS 0.007
CVE-2022-31128
Fine grained permissions are not checked in Tuleap
Published 2022-08-01 · Modified
5.4EPSS 0.006
CVE-2023-48715
Tuleap vulnerable to Cross-site Scripting on the edition page of a release
Published 2023-12-11 · Modified
5.4EPSS 0.005
CVE-2023-30619
XSS in the tooltip via an artifact title
Published 2023-05-04 · Modified
5.4EPSS 0.005
CVE-2023-35929
Tuleap Cross-site Scripting vulnerability in the card field of the agile dashboard apps
Published 2023-07-25 · Modified
5.4EPSS 0.005
CVE-2025-27094
Tuleap allows default values to be cleared from field configuration
Published 2025-03-03 · Analyzed
5.4EPSS 0.004
CVE-2024-52599
Tuleap vulnerable to XSS in the Gantt chart of the tracker plugin
Published 2024-12-09 · Analyzed
5.4EPSS 0.003
CVE-2025-27156
Tuleap allows content injection via emails sent by the mass emailing features
Published 2025-03-04 · Analyzed
5.4EPSS 0.003
CVE-2025-53541
Tuleap is vulnerable to XSS attacks when displaying the children of a parent artifact
Published 2025-07-29 · Analyzed
5.4EPSS 0.002
CVE-2025-64499
Tuleap is missing CSRF protections for its planning management API
Published 2025-12-08 · Analyzed
5.4EPSS 0.001
CVE-2025-30209
Tuleap has improper permission handling in the REST endpoints and release notes display of the FRS plugin
Published 2025-03-31 · Analyzed
5.3EPSS 0.004
CVE-2025-24029
Artifact permissions are not verified in the Cross Tracker Search widget in Tuleap
Published 2025-02-03 · Analyzed
5.3EPSS 0.004
CVE-2025-54877
Tuleap's special and always there fields permissions are not verified in cross-tracker search
Published 2025-08-29 · Analyzed
5.3EPSS 0.003
CVE-2025-52899
Tuleap vulnerable to user enumeration via the lost password form
Published 2025-07-29 · Analyzed
5.3EPSS 0.003
CVE-2024-47766
Permissions are incorrectly verified for project administrators in the cross tracker search widget
Published 2024-10-14 · Analyzed
4.9EPSS 0.005
1 / 2Next →