Roundup-tracker

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    14
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-53865

    In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).

    Last Modified: Apr 15, 2026
    Published: Jul 13, 2025

    CVE-2024-39125

    Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

    Last Modified: Mar 19, 2025
    Published: Jul 17, 2024

    CVE-2024-39126

    Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

    Last Modified: Mar 13, 2025
    Published: Jul 17, 2024

    CVE-2024-39124

    In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.

    Last Modified: Nov 21, 2024
    Published: Jul 17, 2024

    CVE-2012-6133

    Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

    Last Modified: Nov 21, 2024
    Published: Jan 30, 2020
    Items Per Page