CVE-2018-7538: Enalean Tuleap

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.

Affected products

  • Enalean Tuleap: before 9.18 (fixed in 9.18)

Published 2018-03-12. Last modified 2026-06-17.