Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-40896 OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project ca… Openproject 17.3.0+ Fix from $1,9502026-04-20 HIGH 7.4 CVE-2026-33667 OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_… Openproject 17.3.0+ Fix from $1,9502026-04-15 HIGH 8.1 CVE-2026-34717 OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat… Openproject 17.2.3+ Fix from $1,9502026-04-02 HIGH 7.2 CVE-2026-32698 OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL i… Openproject 16.6.9 / 17.0.6+ Fix from $1,9502026-03-18 MEDIUM 5.4 CVE-2026-32703 OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories modul… Openproject 16.6.9 / 17.0.6+ Fix from $1,6002026-03-18 HIGH 7.1 CVE-2026-30239 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned… Openproject 17.2.0+ Fix from $1,9502026-03-11 MEDIUM 6.5 CVE-2026-30235 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenPr… Openproject 17.2.0+ Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2026-30234 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions ca… Openproject 17.2.0+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-27723 OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belongin… Openproject 17.0.5 / 17.1.2+ Fix from $1,6002026-03-05 MEDIUM 6.7 CVE-2026-24777 OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock use… Openproject 17.0.2+ Fix from $1,6002026-02-09 CRITICAL 9.9 CVE-2026-25763 OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis… Openproject 16.6.7 / 17.0.3+ Fix from $2,3002026-02-06 CRITICAL 9.0 CVE-2026-24772 OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced… Openproject 17.0.2+ Fix from $2,3002026-01-28 HIGH 7.3 CVE-2026-24775 OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents based on BlockNote, OpenProject m… Openproject 17.0.2+ Fix from $1,9502026-01-28 HIGH 8.8 CVE-2026-24685 OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability … Openproject 16.6.6 / 17.0.2+ Fix from $1,9502026-01-28 MEDIUM 6.5 CVE-2026-23646 OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to vi… Openproject 16.6.5+ Fix from $1,6002026-01-19 MEDIUM 5.4 CVE-2026-23625 OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a stored cross-site scripting vu… Openproject 16.6.5+ Fix from $1,6002026-01-19 MEDIUM 6.5 CVE-2026-22603 OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint… Openproject 16.6.2+ Fix from $1,6002026-01-10 MEDIUM 5.3 CVE-2026-22604 OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST requ… Openproject 16.6.2+ Fix from $1,6002026-01-10 CRITICAL 9.1 CVE-2026-22600 OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun… Openproject 16.6.4+ Fix from $2,3002026-01-10 HIGH 7.2 CVE-2026-22601 OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut… Openproject 16.6.2+ Fix from $1,9502026-01-10 MEDIUM 5.4 CVE-2025-24892 OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input… Openproject 15.2.1+ Fix from $1,6002025-02-10 MEDIUM 6.1 CVE-2024-41801 OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged … Openproject 14.3.0+ Fix from $1,6002024-07-25 MEDIUM 5.4 CVE-2024-35224 OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This depend… Openproject 13.4.2 / 14.0.2+ Fix from $1,6002024-05-23 HIGH 7.5 CVE-2023-33960 OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote… Openproject 12.5.6+ Fix from $1,9502023-06-01 MEDIUM 6.5 CVE-2023-31140 OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms t… Openproject 12.5.4+ Fix from $1,6002023-05-08 HIGH 8.8 CVE-2021-43830 OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For a… Openproject 12.0.4+ Fix from $1,9502021-12-14 MEDIUM 6.5 CVE-2021-32763 OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `… Openproject 11.3.3+ Fix from $1,6002021-07-20 MEDIUM 6.1 CVE-2019-17092 An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTM… Openproject 9.0.4 / 10.0.2+ Fix from $1,6002019-10-09 HIGH 8.1 CVE-2019-11600EPSS 80% A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id… Openproject 8.3.2+ Fix from $1,9502019-05-13 HIGH 8.1 CVE-2017-11667 OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leve… Openproject after 6.1.5 Fix from $1,9502017-07-26