Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

openproject — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in openproject, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the openProject project, focusing on specific weakness types and their associated tags within the product ecosystem. The collection gathers known security flaws affecting openProject, spanning the full historical range of publicly disclosed issues. Readers can use this resource to track vendor advisories, understand the nature of specific weakness classes, and review the complete vulnerability history for the product.

Vendor: opf

CVE ID Title CVSS Severity Published
CVE-2026-55095 OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields CWE-862 5.3 Medium 2026-08-20
CVE-2026-67529 OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check) CWE-200 4.3 Medium 2026-07-30
CVE-2026-67528 OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposure CWE-863 4.3 Medium 2026-07-30
CVE-2026-67527 OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks" CWE-862 7.6 High 2026-07-30
CVE-2026-44733 OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements CWE-620 5.9 Medium 2026-06-26
CVE-2026-44731 OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosure CWE-639 4.3 Medium 2026-06-26
CVE-2026-44732 OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources CWE-639 4.3 Medium 2026-06-26
CVE-2026-44734 OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename CWE-862 6.5 Medium 2026-06-26
CVE-2026-44735 OpenProject: Shares API Information Disclosure CWE-863 6.5 Medium 2026-06-26
CVE-2026-44696 OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltration CWE-79 5.7 Medium 2026-06-26
CVE-2026-49355 OpenProject: Private work package data disclosure through single meeting agenda item API CWE-200 4.3 Medium 2026-06-26
CVE-2026-44736 OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects CWE-200 6.5 Medium 2026-06-26
CVE-2026-46386 OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal` CWE-502 9.9 Critical 2026-06-26
CVE-2026-52780 OpenProject: Cache store poisoning leads to Remote Code Execution (RCE) CWE-20 9.6 Critical 2026-06-26
CVE-2026-52779 OpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projects CWE-639 5.4 Medium 2026-06-26
CVE-2026-47193 OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks CWE-200 7.5 High 2026-06-26
CVE-2026-52781 OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter "description" CWE-79 6.4 Medium 2026-06-26
CVE-2026-52782 OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources CWE-639 9.9 Critical 2026-06-26
CVE-2026-52783 OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others "storage.<id>.httpx_access_token" leads to Sensitive Data Exposure CWE-313 8.2 High 2026-06-26
CVE-2026-52784 OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]" CWE-352 8.8 High 2026-06-26
CVE-2026-52785 OpenProject: SQL injection in timestamps functionality CWE-89 9.9 Critical 2026-06-26
CVE-2026-40896 OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup CWE-367 6.5 Medium 2026-04-20
CVE-2026-33667 OpenProject: 2FA OTP Verification Missing Rate Limiting CWE-307 7.4 High 2026-04-15
CVE-2026-34717 OpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_string CWE-89 9.9 Critical 2026-04-02
CVE-2026-32703 OpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security Policy CWE-79 9.1 Critical 2026-03-18
CVE-2026-32698 OpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code Execution CWE-89 9.1 Critical 2026-03-18
CVE-2026-31974 Blind SSRF on OpenProject instance via webhooks CWE-918 3.0 Low 2026-03-11
CVE-2026-30239 OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets CWE-863 6.5 Medium 2026-03-11
CVE-2026-30236 OpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rate CWE-863 4.3 Medium 2026-03-11
CVE-2026-30235 Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobbering CWE-79 6.5 Medium 2026-03-11

All 55 known CVE vulnerabilities affecting openproject with full Chinese analysis, references, and POCs where available.