CVE-2025-30203
Last modified
CVE-2025-30203 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enalean | Tuleap | < 16.4-8 |
| Enalean | Tuleap | < 16.5.99.1742562878 |
| Enalean | Tuleap | >= 16.5, < 16.5-5 |
References
- https://github.com/Enalean/tuleap/security/advisories/GHSA-39gx-34fc-rx6rThird Party Advisory
- https://tuleap.net/plugins/tracker/?aid=42243Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-30203?
How severe is CVE-2025-30203?
How do I fix CVE-2025-30203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30198ECOVACS robot vacuums and base stations communicate via an i…6.3
- CVE-2025-30199ECOVACS vacuum robot base stations do not validate firmware …7.5
- CVE-2025-3020An low privileged remote Attacker can execute arbitrary web …5.4
- CVE-2025-30200ECOVACS robot vacuums and base stations communicate via an i…6.3
- CVE-2025-30201Wazuh is a free and open source platform used for threat pre…9.1
- CVE-2025-30202vLLM is a high-throughput and memory-efficient inference and…7.5
- CVE-2025-30204golang-jwt is a Go implementation of JSON Web Tokens. Starti…7.5
- CVE-2025-30205kanidim-provision is a helper utility that uses kanidm's API…7.6
- CVE-2025-30206Dpanel is a Docker visualization panel system which provides…9.8
- CVE-2025-30207Kirby is an open-source content management system. A vulnera…7.5
- CVE-2025-30208Vite, a provider of frontend development tooling, has a vuln…7.5
- CVE-2025-30209Tuleap is an Open Source Suite to improve management of soft…5.3
Are you affected by CVE-2025-30203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
