Search CVE reports


Toggle filters

1 – 10 of 14 results


CVE-2025-53865

Medium priority
Needs evaluation

In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup Not in release Not in release Not in release — —
Show less packages

CVE-2024-39126

Medium priority
Needs evaluation

Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup Not in release Not in release Not in release Not in release —
Show less packages

CVE-2024-39125

Medium priority
Needs evaluation

Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup Not in release Not in release Not in release Not in release —
Show less packages

CVE-2024-39124

Medium priority
Needs evaluation

In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup Not in release Not in release Not in release Not in release —
Show less packages

CVE-2012-6133

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup — — — — —
Show less packages

CVE-2019-10904

Medium priority
Fixed

Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup — — — — Not in release
Show less packages

CVE-2014-6276

Medium priority

Some fixes available 3 of 4

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup — — — — —
Show less packages

CVE-2012-6131

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup — — — — —
Show less packages

CVE-2012-6130

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup — — — — —
Show less packages

CVE-2012-6132

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.

1 affected package

roundup

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundup — — — — —
Show less packages