Enalean develops Tuleap, a web-based project and portfolio management platform widely deployed in enterprise and collaborative development environments, whose vulnerability exposure recurs consistently across the platform's codebases. The vendor's disclosure profile centers on application-layer weaknesses endemic to web-facing software: cross-site scripting, cross-site request forgery, SQL injection, and authorization and privilege-handling flaws that reflect the input-validation and access-control demands of a multi-tenant web application. Although the vulnerability volume is moderate for a platform of Tuleap's scope and adoption, the tendency toward public exploit availability suggests the weaknesses have practical demonstrability and relevance to downstream defenders. Defenders should treat Tuleap patches as part of their regular vulnerability intake and prioritize remediation of web-application input-handling and authorization defects; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enalean over time
Signals from CVEs in this vendor scope (68 CVEs).
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7411HIGH An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a p | Oct 30, 2017 | 8.8 | 81 | NO | YES |
CVE-2017-7981HIGH Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used wit | Apr 29, 2017 | 8.8 | 48 | NO | YES |
CVE-2018-7538CRITICAL A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands. | Mar 12, 2018 | 9.8 | 43 | NO | YES |
CVE-2014-8791MEDIUM project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute ar | Dec 2, 2014 | 6.0 | 41 | NO | YES |
CVE-2014-7178HIGH Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function. | Nov 28, 2014 | 9.3 | 34 | NO | YES |
CVE-2014-7176MEDIUM SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman. | Nov 4, 2014 | 6.5 | 33 | NO | YES |
CVE-2018-17298CRITICAL An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password. | Sep 21, 2018 | 9.8 | 32 | NO | NO |
CVE-2021-41154HIGH Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository | Oct 18, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-41148HIGH Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions | Oct 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-43806HIGH Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when | Dec 15, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (68 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enalean.
Media articles that mention a CVE ID that affects a product developed by Enalean — matched by CVE ID, not by vendor name.