Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Enalean

First CVE: Oct 31, 2014Active for: 12 yearsTotal CVEs: 68
35.3
VTI Score
Medium

Enalean develops Tuleap, a web-based project and portfolio management platform widely deployed in enterprise and collaborative development environments, whose vulnerability exposure recurs consistently across the platform's codebases. The vendor's disclosure profile centers on application-layer weaknesses endemic to web-facing software: cross-site scripting, cross-site request forgery, SQL injection, and authorization and privilege-handling flaws that reflect the input-validation and access-control demands of a multi-tenant web application. Although the vulnerability volume is moderate for a platform of Tuleap's scope and adoption, the tendency toward public exploit availability suggests the weaknesses have practical demonstrability and relevance to downstream defenders. Defenders should treat Tuleap patches as part of their regular vulnerability intake and prioritize remediation of web-application input-handling and authorization defects; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
68
Total CVEs
More Total CVEs than 99% of tracked vendors
7.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Enalean over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2014
11 years ago
Most Recent CVE
Feb 2, 2026
172 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (68 CVEs).

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7411HIGH
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a p
Oct 30, 20178.881NOYES
CVE-2017-7981HIGH
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used wit
Apr 29, 20178.848NOYES
CVE-2018-7538CRITICAL
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.
Mar 12, 20189.843NOYES
CVE-2014-8791MEDIUM
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute ar
Dec 2, 20146.041NOYES
CVE-2014-7178HIGH
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
Nov 28, 20149.334NOYES
CVE-2014-7176MEDIUM
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.
Nov 4, 20146.533NOYES
CVE-2018-17298CRITICAL
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
Sep 21, 20189.832NONO
CVE-2021-41154HIGH
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository
Oct 18, 20218.828NONO
CVE-2021-41148HIGH
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions
Oct 15, 20218.828NONO
CVE-2021-43806HIGH
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when
Dec 15, 20218.827NONO
View all 68 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products68 CVEs
76%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network64 (94.1%)
Unknown4 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (94.1%)
High0 (0.0%)
Unknown4 (5.9%)
User Interaction
None36 (52.9%)
Unknown4 (5.9%)
Required28 (41.2%)
Privileges Required
Low36 (52.9%)
High12 (17.6%)
None16 (23.5%)
Unknown4 (5.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (68 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.9% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
10.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Enalean.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Enalean — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Enalean's Products

View all 2 CNAs →

Top CWEs