Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

opf — Vulnerabilities & Security Advisories 55

Browse all 55 CVE security advisories affecting opf. AI-powered Chinese analysis, POCs, and references for each vulnerability.

opf is a software platform primarily utilized for managing and optimizing operational workflows, often serving as a critical infrastructure component in enterprise environments. With thirty-four recorded Common Vulnerabilities and Exposures (CVEs), the system has historically exhibited significant security weaknesses. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, allowing attackers to gain unauthorized access or disrupt service integrity. Notable incidents highlight the severity of these defects, particularly where insufficient input validation led to arbitrary command execution. The accumulation of these CVEs suggests persistent challenges in the development lifecycle regarding secure coding practices and rigorous testing protocols. Organizations relying on opf must prioritize immediate patching and continuous monitoring to mitigate the risk of exploitation, given the platform’s exposure to high-impact attack vectors that compromise both data confidentiality and system availability.

Found 55 results / 55 Clear Filters
Top products by opf: openproject
CVE ID Title CVSS Severity Published
CVE-2026-55095 OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields — openproject CWE-862 5.3 Medium 2026-08-20
CVE-2026-67529 OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check) — openproject CWE-200 4.3 Medium 2026-07-30
CVE-2026-67528 OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposure — openproject CWE-863 4.3 Medium 2026-07-30
CVE-2026-67527 OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks" — openproject CWE-862 7.6 High 2026-07-30
CVE-2026-44733 OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements — openproject CWE-620 5.9 Medium 2026-06-26
CVE-2026-44731 OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosure — openproject CWE-639 4.3 Medium 2026-06-26
CVE-2026-44732 OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources — openproject CWE-639 4.3 Medium 2026-06-26
CVE-2026-44734 OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename — openproject CWE-862 6.5 Medium 2026-06-26
CVE-2026-44735 OpenProject: Shares API Information Disclosure — openproject CWE-863 6.5 Medium 2026-06-26
CVE-2026-44696 OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltration — openproject CWE-79 5.7 Medium 2026-06-26
CVE-2026-49355 OpenProject: Private work package data disclosure through single meeting agenda item API — openproject CWE-200 4.3 Medium 2026-06-26
CVE-2026-44736 OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects — openproject CWE-200 6.5 Medium 2026-06-26
CVE-2026-46386 OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal` — openproject CWE-502 9.9 Critical 2026-06-26
CVE-2026-52780 OpenProject: Cache store poisoning leads to Remote Code Execution (RCE) — openproject CWE-20 9.6 Critical 2026-06-26
CVE-2026-52779 OpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projects — openproject CWE-639 5.4 Medium 2026-06-26
CVE-2026-47193 OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks — openproject CWE-200 7.5 High 2026-06-26
CVE-2026-52781 OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter "description" — openproject CWE-79 6.4 Medium 2026-06-26
CVE-2026-52782 OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources — openproject CWE-639 9.9 Critical 2026-06-26
CVE-2026-52783 OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others "storage.<id>.httpx_access_token" leads to Sensitive Data Exposure — openproject CWE-313 8.2 High 2026-06-26
CVE-2026-52784 OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]" — openproject CWE-352 8.8 High 2026-06-26
CVE-2026-52785 OpenProject: SQL injection in timestamps functionality — openproject CWE-89 9.9 Critical 2026-06-26
CVE-2026-40896 OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup — openproject CWE-367 6.5 Medium 2026-04-20
CVE-2026-33667 OpenProject: 2FA OTP Verification Missing Rate Limiting — openproject CWE-307 7.4 High 2026-04-15
CVE-2026-34717 OpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_string — openproject CWE-89 9.9 Critical 2026-04-02
CVE-2026-32703 OpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security Policy — openproject CWE-79 9.1 Critical 2026-03-18
CVE-2026-32698 OpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code Execution — openproject CWE-89 9.1 Critical 2026-03-18
CVE-2026-31974 Blind SSRF on OpenProject instance via webhooks — openproject CWE-918 3.0 Low 2026-03-11
CVE-2026-30239 OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets — openproject CWE-863 6.5 Medium 2026-03-11
CVE-2026-30236 OpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rate — openproject CWE-863 4.3 Medium 2026-03-11
CVE-2026-30235 Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobbering — openproject CWE-79 6.5 Medium 2026-03-11

This page lists every published CVE security advisory associated with opf. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.