Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

openproject — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in openproject, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the openProject project, focusing on specific weakness types and their associated tags within the product ecosystem. The collection gathers known security flaws affecting openProject, spanning the full historical range of publicly disclosed issues. Readers can use this resource to track vendor advisories, understand the nature of specific weakness classes, and review the complete vulnerability history for the product.

Vendor: opf

CVE ID Title CVSS Severity Published
CVE-2026-30234 OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR) CWE-22 6.5 Medium 2026-03-11
CVE-2026-27723 OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projects CWE-284 4.3 Medium 2026-03-05
CVE-2026-24777 OpenProject has Improper Access Control on User Management allows user managers to lock admin accounts CWE-862 6.7 Medium 2026-02-09
CVE-2026-25763 Command Injection on OpenProject repositories leads to Remote Code Execution CWE-78 6.5AI Medium AI 2026-02-06
CVE-2026-25764 OpenProject vulnerable to Stored HTML injection CWE-80 3.5 Low 2026-02-06
CVE-2026-24776 OpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transfer CWE-639 4.3 Medium 2026-02-06
CVE-2026-24775 OpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor Extension CWE-345 6.3 Medium 2026-01-28
CVE-2026-24772 OpenProject has SSRF and CSWSH in Hocuspocus Synchronization Server CWE-345 8.9 High 2026-01-28
CVE-2026-24685 OpenProject has Argument Injection on Repository module that allows Arbitrary File Write CWE-77 7.5AI High AI 2026-01-28
CVE-2026-23721 OpenProject users with "View Members" permission in any project can view all Group memberships CWE-862 4.3 Medium 2026-01-19
CVE-2026-23646 OpenProject users can delete other user's session, causing them to be logged out CWE-488 6.5 Medium 2026-01-19
CVE-2026-23625 OpenProject has stored XSS regression using attachments and script-src self CWE-79 8.7 High 2026-01-19
CVE-2026-22605 OpenProject is Vulnerable to Insecure Direct Object Reference in Meetings CWE-284 4.3 Medium 2026-01-10
CVE-2026-22604 OpenProject is vulnerable to user enumeration via the change password function CWE-200 5.3 - 2026-01-10
CVE-2026-22603 OpenProject has no protection against brute-force attacks in the Change Password function CWE-307 9.8 - 2026-01-10
CVE-2026-22602 OpenProject is Vulnerable to User Enumeration via User ID CWE-200 3.5 Low 2026-01-10
CVE-2026-22601 OpenProject is Vulnerable to Code Execution in E-Mail function CWE-77 7.2 - 2026-01-10
CVE-2026-22600 OpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG Coder CWE-200 9.1 Critical 2026-01-10
CVE-2025-24892 OpenProject stored HTML injection vulnerability CWE-79 3.5 Low 2025-02-10
CVE-2024-41801 OpenProject packaged installation has Open Redirect Vulnerability in Sign-In in default configuration CWE-601 4.7 Medium 2024-07-25
CVE-2024-35224 Stored Cross-Site Scripting (XSS) in OpenProject CWE-80 7.6 High 2024-05-23
CVE-2023-33960 OpenProject vulnerable to project identifier information leakage through robots.txt CWE-200 7.5 High 2023-06-01
CVE-2023-31140 OpenProject user sessions not terminated after activation of 2FA CWE-613 4.8 Medium 2023-05-08
CVE-2021-43830 SQL injection in OpenProject CWE-89 7.4 High 2021-12-14
CVE-2021-32763 Regular Expression Denial of Service in OpenProject forum messages CWE-400 4.3 Medium 2021-07-20

All 55 known CVE vulnerabilities affecting openproject with full Chinese analysis, references, and POCs where available.