VYPR

Openproject

by Opf

Source repositories

CVEs (57)

  • CVE-2026-25763CriFeb 6, 2026
    risk 0.64cvss 9.9epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest…

  • CVE-2026-22600CriJan 10, 2026
    risk 0.59cvss 9.1epss 0.00

    OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work…

  • CVE-2026-24772HigJan 28, 2026
    risk 0.58cvss 8.9epss 0.00

    OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The OpenPrioject backend generates an authentication token that is currently valid for 24 hours,…

  • CVE-2026-34717CriApr 2, 2026
    risk 0.57cvss 9.9epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE clauses without parameterization. This issue has been patched in version…

  • CVE-2026-24685HigJan 28, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s repository diff download endpoint (`/projects/:project_id/repository/diff.diff`) when rendering a single…

  • CVE-2026-23625HigJan 19, 2026
    risk 0.57cvss 8.7epss 0.00

    OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a stored cross-site scripting vulnerability in the Roadmap view. OpenProject’s roadmap view renders the “Related work packages” list for each version. When…

  • CVE-2019-11600HigMay 13, 2019
    risk 0.55cvss 8.1epss 0.80

    A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

  • CVE-2017-11667HigJul 26, 2017
    risk 0.53cvss 8.1epss 0.01

    OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.

  • CVE-2026-32703CriMar 18, 2026
    risk 0.52cvss 9.0epss 0.00

    OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to…

  • CVE-2026-32698CriMar 18, 2026
    risk 0.52cvss 9.1epss 0.00

    OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the custom field's name was injected…

  • CVE-2026-33667HigApr 15, 2026
    risk 0.48cvss 7.4epss 0.00

    OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The existing…

  • CVE-2026-22601HigJan 10, 2026
    risk 0.47cvss 7.2epss 0.00

    OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execute arbitrary command by configuring sendmail binary path and sending a test email. This issue has been patched in version 16.6.2.

  • CVE-2026-24777MedFeb 9, 2026
    risk 0.44cvss 6.7epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock users. This functionality should only be possible for users of the application, but they were not supposed to be able to lock…

  • CVE-2026-67527HigJul 30, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id,…

  • CVE-2026-30239MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permission check on the delete action…

  • CVE-2026-30235MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenProject’s Markdown rendering, specifically in the hyperlink handling. This allows an attacker to inject malicious hyperlink…

  • CVE-2026-30234MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the value in markup.bcf is manipulated to contain an absolute or traversal local…

  • CVE-2026-23646MedJan 19, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not properly checked if the…

  • CVE-2024-35224HigMay 23, 2024
    risk 0.42cvss 7.6epss 0.00

    OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header values. This attack requires the…

  • CVE-2026-24775MedJan 28, 2026
    risk 0.41cvss 6.3epss 0.00

    OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents based on BlockNote, OpenProject maintainers added a custom extension in OpenProject version 17.0.0 that allows to mention OpenProject work packages in the…

Page 1 of 3