VYPR

Tuleap

by Enalean

CVEs (71)

  • CVE-2022-39233MedOct 19, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration.…

  • CVE-2022-31032MedJun 29, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.58 authorizations are not properly verified when creating projects or trackers from projects marked as templates. Users can get access to…

  • CVE-2022-24896MedJun 9, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this…

  • CVE-2025-27156MedMar 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in…

  • CVE-2023-35938MedJun 29, 2023
    risk 0.27cvss 4.1epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching from a project visibility that allows restricted users to `Private without restricted`, restricted users that are project administrators keep this access right.…

  • CVE-2024-39902MedJul 22, 2024
    risk 0.24cvss 4.8epss 0.00

    Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the checkbox "Apply same permissions to all sub-items of this folder" in the document…

  • CVE-2025-59040MedSep 18, 2025
    risk 0.21cvss 4.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap…

  • CVE-2014-8791Dec 2, 2014
    risk 0.04cvss epss 0.15

    project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.

  • CVE-2014-7178Nov 28, 2014
    risk 0.03cvss epss 0.05

    Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.

  • CVE-2014-7176Nov 4, 2014
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.

  • CVE-2014-7177Oct 31, 2014
    risk 0.03cvss epss 0.03

    XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.

Page 4 of 4