VYPR

Vendor CVEs

Opf

All CVEs

57 total · sorted by risk
  • CVE-2026-22603MedJan 10, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint (/account/change_password) was not protected by the same brute-force safeguards that apply to the normal login form. In…

  • CVE-2026-22602LowJan 10, 2026
    risk 0.00cvss 3.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-in user can view the full names of other users. Since user IDs are assigned sequentially and predictably (e.g., 1 to 1000), an attacker can extract a complete…

  • CVE-2025-24892LowFeb 10, 2025
    risk 0.00cvss 3.5epss 0.00

    OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not properly escaped before…

  • CVE-2023-33960HigJun 1, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall not be accessed by crawlers. These routes contain project identifiers of all public projects in the…

  • CVE-2023-31140MedMay 8, 2023
    risk 0.00cvss 4.8epss 0.01

    OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms their first two-factor authentication (2FA) device for an account, existing logged in sessions for that user account are not…

  • CVE-2021-43830HigDec 14, 2021
    risk 0.00cvss 7.4epss 0.01

    OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently…

  • CVE-2021-32763MedJul 20, 2021
    risk 0.00cvss 4.3epss 0.01

    OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `quote` method that implements the logic behind the Quote button in the discussion forums, and it uses a regex to strip ``…

Page 2 of 2