Tuleap

Vendor:

First CVE: Oct 31, 2014 · Active for 11 years

68
Total CVEs
More Total CVEs than 99% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tuleap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2014
11 years ago
Most Recent CVE
Feb 2, 2026
176 days ago

CVE Severity & Scoring

Tuleap68 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network64 (94.1%)
Unknown4 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (94.1%)
High0 (0.0%)
Unknown4 (5.9%)
User Interaction
None36 (52.9%)
Unknown4 (5.9%)
Required28 (41.2%)
Privileges Required
Low36 (52.9%)
High12 (17.6%)
None16 (23.5%)
Unknown4 (5.9%)

Top CVEs

Signals from CVEs in this product scope (68 CVEs).

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a p
Oct 30, 20178.881NOYES
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used wit
Apr 29, 20178.848NOYES
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.
Mar 12, 20189.843NOYES
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute ar
Dec 2, 20146.041NOYES
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
Nov 28, 20149.334NOYES
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.
Nov 4, 20146.533NOYES
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
Sep 21, 20189.832NONO
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository
Oct 18, 20218.828NONO
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions
Oct 15, 20218.828NONO
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when
Dec 15, 20218.827NONO

Exploit Exposure

Signals from CVEs in this product scope (68 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
10.3% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (68 CVEs).

Media Mentions

Signals from CVEs in this product scope (68 CVEs).

Top CNAs Publishing CVEs For Tuleap

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1718.80.8%00
7.616.014.8%01
15.7-117.10.6%00