Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Roundup Tracker

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 27

Roundup Tracker is a niche issue-tracking and collaboration platform whose vulnerability profile is concentrated in its single core product. The platform's disclosure history reflects the complexity inherent to web-based issue management systems that handle user input, authentication, and data access controls. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.1
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Roundup Tracker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jul 13, 2025
376 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1444MEDIUM
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.
Dec 31, 20045.031NOYES
CVE-2019-10904MEDIUM
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
Apr 6, 20196.122NONO
CVE-2012-6133MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_mes
Jan 30, 20206.120NONO
CVE-2025-53865MEDIUM
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
Jul 13, 20256.419NONO
CVE-2008-1475MEDIUM
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2)
Mar 24, 20086.419NONO
CVE-2012-6130MEDIUM
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to g
Apr 11, 20144.318NONO
CVE-2024-39126MEDIUM
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
Jul 17, 20245.417NONO
CVE-2024-39125MEDIUM
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
Jul 17, 20245.417NONO
CVE-2024-39124MEDIUM
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
Jul 17, 20245.417NONO
CVE-2012-6131MEDIUM
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to suppo
Apr 11, 20144.317NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network7 (50.0%)
Unknown7 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (50.0%)
High0 (0.0%)
Unknown7 (50.0%)
User Interaction
None2 (14.3%)
Unknown7 (50.0%)
Required5 (35.7%)
Privileges Required
Low5 (35.7%)
High0 (0.0%)
None2 (14.3%)
Unknown7 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Roundup Tracker.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Roundup Tracker — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Roundup Tracker's Products

View all 3 CNAs →

Top CWEs