OpenProject是OpenProject开源的一个基于Web的项目管理软件。 OpenProject 17.0.1之前版本和16.6.5之前版本存在安全漏洞,该漏洞源于权限检查失败,可能导致拥有查看成员权限的用户枚举所有群组及其成员。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opf | openproject | < 16.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-23625 | 8.7 HIGH | OpenProject has stored XSS regression using attachments and script-src self |
| CVE-2026-23646 | 6.5 MEDIUM | OpenProject users can delete other user's session, causing them to be logged out |
No comments yet