Known Vulnerabilities for products from Roundup-tracker
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Roundup-tracker".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-10904 json | Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. | 6.1 - MEDIUM | 2019-04-06 | 2019-04-09 |
| CVE-2014-6276 json | schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow ... | Not Provided | 2016-04-13 | 2026-05-06 |
| CVE-2012-6133 json | Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web s... | 6.1 - MEDIUM | 2020-01-30 | 2020-01-31 |
| CVE-2012-6132 json | Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or H... | Not Provided | 2014-04-10 | 2026-05-06 |
| CVE-2012-6131 json | Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrar... | Not Provided | 2014-04-11 | 2026-05-06 |
| CVE-2012-6130 json | Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject ar... | Not Provided | 2014-04-11 | 2026-05-06 |
| CVE-2010-2491 json | Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrar... | Not Provided | 2010-09-24 | 2026-04-29 |
| CVE-2008-1475 json | The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and ed... | Not Provided | 2008-03-24 | 2026-04-23 |
| CVE-2008-1474 json | Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be rel... | Not Provided | 2008-03-24 | 2026-04-23 |
| CVE-2004-1444 json | Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot do... | Not Provided | 2004-12-31 | 2025-04-03 |
Known software with vulnerabilities from Roundup-tracker
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Roundup-tracker | Roundup | 0.1.0 |