📦 Tuleap

by Enalean

🔍 What is Tuleap?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-31058

HIGH CVSS 7.2 Jun 29, 2022

CVE-2022-31058 is a SQL injection vulnerability in Tuleap's tracker report functionality. Attackers with permission to create new trackers can execute arbitrary SQL queries, potentially leading to dat...

CVE-2021-43806

HIGH CVSS 8.8 Dec 15, 2021

CVE-2021-43806 is an SQL injection vulnerability in Tuleap's CVS repository browsing functionality. Authenticated users with read access to CVS repositories can execute arbitrary SQL queries, potentia...

CVE-2021-41154

HIGH CVSS 8.8 Oct 18, 2021

This vulnerability allows attackers with read access to SVN core repositories in Tuleap to execute arbitrary SQL queries through SQL injection. It affects Tuleap Community and Enterprise Editions befo...

CVE-2021-41148

HIGH CVSS 8.8 Oct 15, 2021

This SQL injection vulnerability in Tuleap Open ALM allows attackers with dashboard editing permissions to execute arbitrary SQL queries. It affects Tuleap Community Edition before version 11.16.99.17...

CVE-2026-24007

MEDIUM CVSS 4.6 Feb 2, 2026

This CSRF vulnerability in Tuleap allows attackers to trick authenticated users into performing unauthorized actions, specifically creating artifact links from releases. All Tuleap users with access t...

CVE-2025-65962

MEDIUM CVSS 4.6 Dec 9, 2025

This CVE-2025-65962 is a Cross-Site Request Forgery (CSRF) vulnerability in Tuleap's tracker field dependencies that allows attackers to modify tracker fields without proper authorization. It affects ...

CVE-2025-64498

MEDIUM CVSS 4.6 Dec 8, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Tuleap project management software that allows attackers to trick authenticated users into changing tracker general settings wit...

CVE-2025-64499

MEDIUM CVSS 4.6 Dec 8, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Tuleap's planning management API. Attackers can trick authenticated users into unknowingly creating, editing, or deleting projec...

CVE-2025-64760

MEDIUM CVSS 4.6 Dec 8, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Tuleap that allows attackers to create or remove tracker triggers without proper authorization. All Tuleap Community Edition ver...

CVE-2025-64497

MEDIUM CVSS 6.5 Dec 8, 2025

This CVE describes an authorization bypass vulnerability in Tuleap's file release system. Attackers can access file release information in projects they shouldn't have permission to view. This affects...

CVE-2025-52899

MEDIUM CVSS 5.3 Jul 29, 2025

This vulnerability in Tuleap's forgot password form allows attackers to enumerate valid usernames by observing differences in response times or error messages. It affects all Tuleap Community Edition ...

CVE-2025-53902

MEDIUM CVSS 4.3 Jul 29, 2025

This CVE describes an authorization bypass vulnerability in Tuleap where authenticated users can access confidential artifact information they shouldn't have permission to view. It affects Tuleap Comm...

CVE-2025-50179

MEDIUM CVSS 4.6 Jun 25, 2025

This CVE describes a cross-site request forgery (CSRF) vulnerability in Tuleap that allows attackers to trick authenticated users into modifying canned responses. The vulnerability affects Tuleap Comm...

CVE-2025-30155

MEDIUM CVSS 4.3 Mar 31, 2025

Tuleap's REST API fails to enforce read permissions on parent trackers, allowing authenticated users to access tracker data they shouldn't have permission to view. This affects all Tuleap installation...

CVE-2025-30203

MEDIUM CVSS 4.8 Mar 31, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Tuleap's RSS widget functionality. Project administrators or users controlling RSS feeds can inject malicious scripts that execute in v...

CVE-2025-29929

MEDIUM CVSS 4.6 Mar 31, 2025

This CSRF vulnerability in Tuleap allows attackers to trick authenticated users into unknowingly submitting or editing artifacts or follow-up comments by exploiting missing CSRF protection in tracker ...

CVE-2025-29766

MEDIUM CVSS 4.6 Mar 31, 2025

CVE-2025-29766 is a Cross-Site Request Forgery (CSRF) vulnerability in Tuleap that allows attackers to trick authenticated users into submitting or editing tracker artifacts and comments without their...

CVE-2025-27401

MEDIUM CVSS 4.6 Mar 4, 2025

This vulnerability in Tuleap allows authenticated users with access to any tracker to delete all criteria filters across all reports by repeatedly creating and deleting reports. This affects all Tulea...

CVE-2025-27099

MEDIUM CVSS 4.8 Mar 3, 2025

This CVE describes a stored cross-site scripting (XSS) vulnerability in Tuleap's tracker semantic timeframe deletion messages. A tracker administrator can inject malicious scripts that execute in the ...

CVE-2025-24029

MEDIUM CVSS 5.3 Feb 3, 2025

CVE-2025-24029 is an improper permissions vulnerability in Tuleap that allows users (including anonymous users in public project dashboards) to access artifacts they shouldn't have permission to view....

CVE-2024-52599

MEDIUM CVSS 5.4 Dec 9, 2024

This vulnerability allows a malicious user with artifact creation permissions in a tracker with a Gantt chart to execute cross-site scripting (XSS) attacks against other users. The attacker can force ...

CVE-2024-47767

MEDIUM CVSS 4.3 Oct 14, 2024

This vulnerability in Tuleap allows users to see tracker names they should not have access to due to improper handling of permissions. It affects all Tuleap Community and Enterprise Edition users runn...

CVE-2024-46988

MEDIUM CVSS 4.8 Oct 14, 2024

This vulnerability in Tuleap allows users to receive email notifications containing information they shouldn't have access to, potentially exposing sensitive development data. It affects all Tuleap Co...

CVE-2024-39902

MEDIUM CVSS 4.8 Jul 22, 2024

This vulnerability in Tuleap's document manager allows users to retain edit or manage permissions on sub-items when permissions are being restricted via the web UI. The checkbox 'Apply same permission...