Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Security Intel Hub 26+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
Medium
Tuleap CSRF Vulnerability (CVE-2026-24007) Advisory
GHSA-7g48-rwqj-ffxw · github.com · 2026-02-03
Tuleap Community Edition < 17.0.99.1768924735 · Tuleap Enterprise Edition < 17.0-9 …
Read more
Medium
Tuleap CVE-2025-65962 Missing CSRF in Tracker Field Dependencies
CVE-2025-65962 · github.com · 2025-12-09
Tuleap Community Edition < 17.0.99.1763803709 · Tuleap Enterprise Edition < 17.0-4 …
Read more
Medium
Tuleap Tracker Trigger Management CSRF Vulnerability (CVE-2025-64760)
CVE-2025-64760 · github.com · 2025-12-09
Tuleap Community Edition < 17.0.99.1763126988 · Tuleap Enterprise Edition < 17.0-3 …
Read more
Medium
Tuleap CSRF Vulnerability (CVE-2025-64498) Advisory
CVE-2025-64498 · github.com · 2025-12-09
Tuleap Community Edition (tuleap) < 17.0.99.1762444754 · Tuleap Enterprise Edition (tuleap) < 17.0-2 …
Read more
High
Tuleap CVE-2025-64497: Admin Access to All Project Releases
CVE-2025-64497 · github.com · 2025-12-09
Tuleap Community Edition < 17.0.99.1762431347 · Tuleap Enterprise Edition < 17.0-2 …
Read more
High
Tuleap CVE-2024-30246 High Severity Vulnerability: Unintended Artifact Data Deletion
CVE-2024-30246 · github.com · 2025-11-19
Tuleap Community Edition >= 14.11.99.34 && < 15.7.99.6 · Tuleap Enterprise Edition >= 15.7-1 && < 15.7-2 …
Read more
Medium
Tuleap File Release System Missing CSRF Protection (CVE-2025-64482)
CVE-2025-64482 · github.com · 2025-11-14
Tuleap Community Edition < 16.13.99.1762267347 · Tuleap Enterprise Edition < 17.0-1 …
Read more
Medium
Tuleap CVE-2021-43782 Indirect LDAP Injection Vulnerability Advisory
CVE-2021-43782 · github.com · 2025-11-10
Tuleap <13.2.99.83 · Tuleap >=13.1-1 && <13.2.4 …
Read more
CVSS 6.5
Tuleap Artifact Link Preview Permission Bypass Fix
github.com · 2025-11-09

### Key Information Summary #### 1. Vulnerability Fix Description: - **Fixes Request**: Fixes request #33608 - **Issue Description**: Preview of a linked artifact with a type does not respect permissi…

Read more
CVSS 5.3
Tuleap CVE-2024-23344 Unauthorized Artifact Readability Vulnerability Advisory
github.com · 2025-11-08

### Vulnerability Key Information #### Vulnerability Description - **Name**: Content of artifacts might be readable by unauthorized users - **CVE ID**: CVE-2024-23344 - **Publisher**: LeSuisse - **Rel…

Read more
CVSS 4.3
Tuleap Permission Bypass Vulnerability (CVE-2025-59040) GHSA Advisory
github.com · 2025-09-20

### Critical Vulnerability Information #### Vulnerability Title Backlog item representations do not verify the permissions of the child trackers #### Vulnerability ID GHSA-67xc-39v9-pffg #### Affected…

Read more
CVSS 5.3
Tuleap Cross-Tracker Search Permission Verification Bypass (CVE-2025-54877)
github.com · 2025-08-30

### Critical Vulnerability Information #### Vulnerability Title - **Special and always there fields permissions are not verified in cross-tracker search** #### Severity - **CVSS v3 base metrics**: 5.3…

Read more
CVSS 5.3
Tuleap User Enumeration via Lost Password Form (CVE-2025-52899)
github.com · 2025-07-31

### Critical Vulnerability Information #### Vulnerability Title - **User enumeration via the lost password form** #### Publisher and Date - **LeSuisse** published GHSA-xqf3-xxxf-x3c2 yesterday #### Af…

Read more
CVSS 4.6
Tuleap CVE-2025-50179 Missing CSRF Protection Fix
github.com · 2025-07-06

### Critical Vulnerability Information #### Vulnerability Title - **Missing CSRF protection on tracker reports manipulation** #### Severity - **Level**: Moderate (4.6/10) #### Impact - **Description**…

Read more
CVSS 4.6
Tuleap Tracker Canned Responses CSRF Vulnerability (CVE-2025-48991)
github.com · 2025-07-06

### Critical Vulnerability Information #### Vulnerability Title - **Missing CSRF protection on tracker canned responses administration** #### Severity - **Level**: Moderate - **CVSS v3 Base Metrics**:…

Read more
CVSS 4.3
Tuleap REST API Parent Tracker Read Permission Bypass (CVE-2025-30155)
github.com · 2025-04-01

### Critical Vulnerability Information #### Vulnerability Title - **Read permission not enforced on parent tracker in the REST API** #### Severity - **Moderate** - **CVSS v3 Base Score**: 4.3 / 10 - A…

Read more
CVSS 5.3
Jenkins PRB Plugin Permission Handling Fix
github.com · 2025-04-01

From this webpage screenshot, the following key vulnerability-related information can be extracted: - **Commit ID**: 346f2d5 - **Commit Description**: "Adjust permission handling in the REST endpoints…

Read more
CVSS 5.3
Tuleap FRS Plugin REST Endpoint Improper Permission Handling (CVE-2025-30209)
github.com · 2025-04-01

### Critical Vulnerability Information #### Vulnerability Title - **Improper permission handling in the REST endpoints and release notes display of the FRS plugin** #### Severity - **Moderate** - **CV…

Read more
CVSS 4.8
Tuleap RSS Widget XSS Vulnerability Advisory (CVE-2025-30203)
github.com · 2025-04-01

### Key Information #### Vulnerability Title - **XSS via the content of RSS feeds in the RSS widgets** #### Severity - **Moderate** - **CVSS v3 base metrics:** - Attack vector: Network - Attack comple…

Read more
CVSS 4.6
Tuleap Missing CSRF Protection Vulnerability (CVE-2025-29929) Advisory
github.com · 2025-04-01

### Critical Vulnerability Information #### Vulnerability Title - **Missing CSRF protection on tracker hierarchy administration** #### Severity - **Moderate** - **CVSS v3 base metrics: 4.6/10** - Atta…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.