CVEs we hold for Enalean
Records whose assigning authority named Enalean as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-64760Tuleap has missing CSRF protections in its tracker trigger management systemEnalean tuleap
CVE-2025-64497Tuleap exposes releases for all projects to File Release System project administratorsEnalean tuleap
CVE-2025-64117Tuleap missing CSRF protection in the management of SVN commit rules and immutable tagsEnalean tuleap
CVE-2025-59040Tuleap backlog item representations do not verify the permissions of the child trackersEnalean tuleap
CVE-2025-54877Tuleap's special and always there fields permissions are not verified in cross-tracker searchEnalean tuleap
CVE-2025-53541Tuleap is vulnerable to XSS attacks when displaying the children of a parent artifactEnalean tuleap
CVE-2025-48991Tuleap missing CSRF protection on tracker canned responses administrationEnalean tuleap
CVE-2025-30209Tuleap has improper permission handling in the REST endpoints and release notes display of the FRS pluginEnalean tuleap
CVE-2025-30155Tuleap does not enforce read permissions on parent trackers in the REST APIEnalean tuleap
CVE-2025-29766Tuleap has missing CSRF protections on artifact submission & edition from the tracker viewEnalean tuleap
CVE-2025-27402Tuleap is missing CSRF protections on tracker fields administrative operationsEnalean tuleap
CVE-2025-27401In Tuleap, deleting a report can delete criteria filters in other reportsEnalean tuleap
CVE-2025-27156Tuleap allows content injection via emails sent by the mass emailing featuresEnalean tuleap
CVE-2025-27150Tuleap dumps the Redis password into the generated troubleshooting archivesEnalean tuleap
CVE-2025-27099Tuleap allows XSS via the tracker names used in the semantic timeframe deletion messageEnalean tuleap
CVE-2025-24029Artifact permissions are not verified in the Cross Tracker Search widget in TuleapEnalean tuleap
CVE-2025-22129Initial effort field does not respect field permissions in the Taskboard REST card representation in TuleapEnalean tuleap
CVE-2024-47767Tuleap lists trackers in the quick add actions of the backlog without any permissions checkEnalean tuleap
CVE-2024-47766Permissions are incorrectly verified for project administrators in the cross tracker search widgetEnalean tuleap
CVE-2024-46988Tuleap does not properly check permissions for email notifications in trackersEnalean tuleap
CVE-2024-46980Tuleap vulnerable to XSS in the HTML mail content of the cross reference fieldEnalean tuleap
CVE-2024-39902Tuleap's recursive permissions to document manager folder are not properly appliedEnalean tuleap
CVE-2024-30246Tuleap deleting or moving an artifact can delete values from unrelated artifactsEnalean tuleap
CVE-2023-48715Tuleap vulnerable to Cross-site Scripting on the edition page of a releaseEnalean tuleap
CVE-2023-39521Tuleap vulnerable to Cross-site Scripting on the success message of a kanban deletionEnalean tuleap
CVE-2023-38508Tuleap allows preview of a linked artifact with a type does not respect permissionsEnalean tuleap
CVE-2023-35929Tuleap Cross-site Scripting vulnerability in the card field of the agile dashboard appsEnalean tuleap
CVE-2023-23938Cross-site Scripting (XSS) through the name of a color of select box values in tuleapEnalean tuleap
CVE-2022-39233Tuleap subject to Missing Authorization allowing for branch prefix modificationEnalean tuleap
CVE-2021-41148The update of the CI job targeted by a widget is vulnerable to blind SQL injectionsEnalean tuleap
62 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.