Roundup

Latest version: v2.4.0

Vulnerabilities (31)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2024-39125 72257

Roundup affected versions allow XSS via a SCRIPT element in an HTTP R…

  • <2.4.0
MEDIUM 5.4
CVE-2024-39124 72259

In affected versions of Roundup, classhelpers (_generic.help.html) al…

  • <2.4.0
MEDIUM 5.4
CVE-2024-39126 72258

Roundup affected versions allow XSS via JavaScript in PDF, XML, and S…

  • <2.4.0
MEDIUM 5.4
PVE-2023-58862 58862

Roundup 2.3.0b2 stops adding 'Access-Control-Allow-Credentials' heade…

  • <2.3.0b2
- -
CVE-2011-4969 58898

Roundup 2.1.0b1 updates its dependency 'jquery' to v3.5.1 to include …

  • <2.1.0b1
MEDIUM 4.3
CVE-2019-11358 58863

Roundup 2.1.0b1 updates its dependency 'jquery' to v3.5.1 to include …

  • <2.1.0b1
MEDIUM 6.1
CVE-2012-6708 58897

Roundup 2.1.0b1 updates its dependency 'jquery' to v3.5.1 to include …

  • <2.1.0b1
MEDIUM 6.1
PVE-2023-58899 58899

Roundup 2.1.0b1 includes a fix for a timing attack vulnerability. ht…

  • <2.1.0b1
- -
CVE-2020-7656 58895

Roundup 2.1.0b1 updates its dependency 'jquery' to v3.5.1 to include …

  • <2.1.0b1
MEDIUM 6.1
CVE-2015-9251 58896

Roundup 2.1.0b1 updates its dependency 'jquery' to v3.5.1 to include …

  • <2.1.0b1
MEDIUM 6.1
PVE-2023-58894 58894

Roundup 1.6.0 includes a security fix: XSS on 404 page. https://issu…

  • <1.6.0
- -
PVE-2023-58866 58866

Roundup 1.6.0 includes a security fix: Inadequate CSRF protection. h…

  • <1.6.0
- -
CVE-2019-10904 37025

Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and …

  • ==1.6
MEDIUM 6.1
PVE-2023-58867 58867

Roundup 1.5.1 includes a fix for a XSS vulnerability. https://issues…

  • <1.5.1
- -
PVE-2023-58893 58893

Roundup 1.5.1 includes a security fix: HTML attachments should not be…

  • <1.5.1
- -
PVE-2023-58872 58872

Roundup 1.4.7 disables serving uploaded HTML files content as HTML by…

  • <1.4.7
- -
PVE-2023-58890 58890

Roundup 1.4.7 fixes improper permissions vulnerabilities. https://gi…

  • <1.4.7
- -
CVE-2012-6133 37744

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before…

  • <1.4.20
MEDIUM 6.1
CVE-2012-6130 33162

Cross-site scripting (XSS) vulnerability in the history display in Ro…

  • <1.4.20
MEDIUM 4.3
CVE-2012-6131 33163

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup …

  • <1.4.20
MEDIUM 4.3
PVE-2023-58870 58870

Roundup 1.4.17 includes a security fix: An user which didn't have acc…

  • <1.4.17
- -
PVE-2023-58892 58892

Roundup 1.4.17 includes a fix for an unsafe password handling vulnera…

  • <1.4.17
- -
PVE-2023-58891 58891

Roundup 1.4.11 includes a fix for a privileges escalation vulnerabili…

  • <1.4.11
- -
PVE-2023-58871 58871

Roundup 1.4.11 includes a security fix: If user hasn't permission on …

  • <1.4.11
- -
CVE-2004-1444 61226

Directory traversal vulnerability in Roundup 0.6.4 and earlier allows…

  • <=0.6.4
MEDIUM 5.0
PVE-2023-58882 58882

Roundup 0.6.0b4 includes a fix for a XSS vulnerability. https://gith…

  • <0.6.0b4
- -
CVE-2014-6276 54086

schema.py in Roundup before 1.5.1 does not properly limit attributes …

  • >=0,<1.5.1
MEDIUM 4.3
CVE-2008-1475 54035

The xml-rpc server in Roundup 1.4.4 does not check property permissio…

  • >=0,<1.4.5
MEDIUM 6.4
CVE-2008-1474 54034

Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unk…

  • >=0,<1.4.4
MEDIUM 4.3
CVE-2012-6132 54079

Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 all…

  • >=0,<1.4.20
MEDIUM 4.3
CVE-2010-2491 54052

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup …

  • >=0,<1.4.14
MEDIUM 4.3