Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tuleap MEDIUM 5.4
CVE-2021-41142

Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. There is a cross-site scripting v…

Fix: 11.17.99.146 / 12.11-2+
Fix from $1,600 2021-10-14
Tuleap CRITICAL 9.8
CVE-2018-17298

An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.

Fix: 10.5+
Fix from $2,300 2018-09-21
Tuleap CRITICAL 9.8
CVE-2018-7538

A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute ar…

Fix: 9.18+
Fix from $2,300 2018-03-12
Tuleap HIGH 8.8
CVE-2018-7634

An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functi…

Patch available
Fix from $1,950 2018-03-01
Tuleap HIGH 8.8
CVE-2017-7411EPSS 67%

An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the …

Fix: after 9.6
Fix from $1,950 2017-10-30
Tuleap HIGH 8.8
CVE-2017-7981EPSS 16%

Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the pro…

Fix: 9.7+
Fix from $1,950 2017-04-29
Tuleap MEDIUM 6.0
CVE-2014-8791EPSS 15%

project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object i…

No fix yet
Fix from $1,600 2014-12-02
Tuleap HIGH 9.3
CVE-2014-7178EPSS 5%

Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP…

Fix: after 7.5.99.5
Fix from $1,950 2014-11-28
Tuleap MEDIUM 6.5
CVE-2014-7176

SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt p…

Fix: after 7.5
Fix from $1,600 2014-11-04