CVE-2025-30203
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2025-30203 is a newly disclosed vulnerability affecting Tuleap, an open-source software development and collaboration suite. This issue enables attackers to perform cross-site scripting (XSS) attacks through the content of RSS feeds in Tuleap's RSS widgets. Project administrators or individuals with control over used RSS feeds could exploit this vulnerability, compelling victims to execute unintended code. The Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8 have been released as official patches to mitigate this security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.