Roundup

Vendor:

First CVE: Dec 31, 2004 · Active for 21 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Roundup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jul 13, 2025
378 days ago

CVE Severity & Scoring

Roundup14 CVEs
All CVEs352,719 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network7 (50.0%)
Unknown7 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (50.0%)
High0 (0.0%)
Unknown7 (50.0%)
User Interaction
None2 (14.3%)
Unknown7 (50.0%)
Required5 (35.7%)
Privileges Required
Low5 (35.7%)
High0 (0.0%)
None2 (14.3%)
Unknown7 (50.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.
Dec 31, 20045.031NOYES
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
Apr 6, 20196.122NONO
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_mes
Jan 30, 20206.120NONO
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
Jul 13, 20256.419NONO
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2)
Mar 24, 20086.419NONO
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to g
Apr 11, 20144.318NONO
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
Jul 17, 20245.417NONO
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
Jul 17, 20245.417NONO
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
Jul 17, 20245.417NONO
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to suppo
Apr 11, 20144.317NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Roundup

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.616.11.6%00
1.4.944.32.1%00
1.4.844.32.1%00
1.4.744.32.1%00
1.4.644.32.1%00
1.4.544.32.1%00
1.4.444.32.1%00
1.4.344.32.1%00
1.4.264.71.9%00
1.4.1834.31.9%00
1.4.1734.31.9%00
1.4.1634.31.9%00
1.4.1534.31.9%00
1.4.1434.31.9%00
1.4.1334.31.9%00
1.4.1244.32.1%00
1.4.1144.32.1%00
1.4.1044.32.1%00
1.4.164.71.9%00
1.4.064.71.9%00