VYPR

Openproject

by Opf

Source repositories

CVEs (57)

  • CVE-2026-47193HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.

  • CVE-2026-46386CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a…

  • CVE-2026-44736MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary…

  • CVE-2026-44735MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details for ALL work packages in a project to any user with the view_shared_work_packages permission. The authorization check operates at…

  • CVE-2026-44734MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and…

  • CVE-2026-44733MedJun 26, 2026
    risk 0.00cvss 5.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation flaw in the change password behavior allows…

  • CVE-2026-44732MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update,…

  • CVE-2026-44731MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all…

  • CVE-2026-44696MedJun 26, 2026
    risk 0.00cvss 5.7epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitization. This configuration permits essentially all CSS properties in style…

  • CVE-2026-22604MedJan 10, 2026
    risk 0.00cvss 5.3epss 0.00

    OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST request to the /account/change_password endpoint with an arbitrary User ID as the password_change_user_id parameter, the resulting…

  • CVE-2026-22603MedJan 10, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint (/account/change_password) was not protected by the same brute-force safeguards that apply to the normal login form. In…

  • CVE-2026-22602LowJan 10, 2026
    risk 0.00cvss 3.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-in user can view the full names of other users. Since user IDs are assigned sequentially and predictably (e.g., 1 to 1000), an attacker can extract a complete…

  • CVE-2025-24892LowFeb 10, 2025
    risk 0.00cvss 3.5epss 0.00

    OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not properly escaped before…

  • CVE-2023-33960HigJun 1, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall not be accessed by crawlers. These routes contain project identifiers of all public projects in the…

  • CVE-2023-31140MedMay 8, 2023
    risk 0.00cvss 4.8epss 0.01

    OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms their first two-factor authentication (2FA) device for an account, existing logged in sessions for that user account are not…

  • CVE-2021-43830HigDec 14, 2021
    risk 0.00cvss 7.4epss 0.01

    OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently…

  • CVE-2021-32763MedJul 20, 2021
    risk 0.00cvss 4.3epss 0.01

    OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `quote` method that implements the logic behind the Quote button in the discussion forums, and it uses a regex to strip ``…

Page 3 of 3