CVEs we hold for Opf
Records whose assigning authority named Opf as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-67529OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs…opf openproject
CVE-2026-67528OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposureopf openproject
CVE-2026-67527OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"opf openproject
CVE-2026-55095OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fieldsopf openproject
CVE-2026-52784OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]"opf openproject
CVE-2026-52783OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others…opf openproject
CVE-2026-52782OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter…opf openproject
CVE-2026-52781OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter…opf openproject
CVE-2026-52780OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)opf openproject
CVE-2026-52779OpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from…opf openproject
CVE-2026-49355OpenProject: Private work package data disclosure through single meeting agenda item APIopf openproject
CVE-2026-47193OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checksopf openproject
CVE-2026-46386OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME`…opf openproject
CVE-2026-44736OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjectsopf openproject
CVE-2026-44734OpenProject: Improper Access Control on OpenProject through the POST request to…opf openproject
CVE-2026-44733OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password…opf openproject
CVE-2026-44732OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized…opf openproject
CVE-2026-44731OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in…opf openproject
CVE-2026-44696OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltrationopf openproject
CVE-2026-40896OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookupopf openproject
CVE-2026-34717OpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_stringopf openproject
CVE-2026-32703OpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security Policyopf openproject
CVE-2026-32698OpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code Executionopf openproject
CVE-2026-30239OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgetsopf openproject
CVE-2026-30236OpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rateopf openproject
CVE-2026-30235Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobberingopf openproject
CVE-2026-30234OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR)opf openproject
CVE-2026-27723OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projectsopf openproject
CVE-2026-25763Command Injection on OpenProject repositories leads to Remote Code Executionopf openproject
CVE-2026-24777OpenProject has Improper Access Control on User Management allows user managers to lock admin accountsopf openproject
CVE-2026-24776OpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transferopf openproject
CVE-2026-24775OpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote…opf openproject
CVE-2026-24685OpenProject has Argument Injection on Repository module that allows Arbitrary File Writeopf openproject
CVE-2026-23721OpenProject users with "View Members" permission in any project can view all Group membershipsopf openproject
CVE-2026-23646OpenProject users can delete other user's session, causing them to be logged outopf openproject
CVE-2026-23625OpenProject has stored XSS regression using attachments and script-src selfopf openproject
CVE-2026-22605OpenProject is Vulnerable to Insecure Direct Object Reference in Meetingsopf openproject
CVE-2026-22604OpenProject is vulnerable to user enumeration via the change password functionopf openproject
CVE-2026-22603OpenProject has no protection against brute-force attacks in the Change Password functionopf openproject
CVE-2026-22600OpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG Coderopf openproject
CVE-2024-41801OpenProject packaged installation has Open Redirect Vulnerability in Sign-In in default configurationopf openproject
CVE-2023-33960OpenProject vulnerable to project identifier information leakage through robots.txtopf openproject
55 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.