Openproject

Openproject

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 09.02.2026 18:28:45
  • Zuletzt bearbeitet 11.02.2026 18:28:40

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock users. This functionality should only be possible for users of the application, but they were not suppos...

  • EPSS 0.02%
  • Veröffentlicht 06.02.2026 22:10:13
  • Zuletzt bearbeitet 13.02.2026 19:07:56

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rende...

  • EPSS 0.02%
  • Veröffentlicht 06.02.2026 22:10:09
  • Zuletzt bearbeitet 13.02.2026 19:04:45

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The application does not escape HTML tags, an attacker wit...

  • EPSS 0.03%
  • Veröffentlicht 06.02.2026 18:15:58
  • Zuletzt bearbeitet 23.02.2026 18:14:32

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an agenda item to a different section was not properly checking if the target meeting section is part of the same meeting (or is the b...

  • EPSS 0.02%
  • Veröffentlicht 28.01.2026 18:10:46
  • Zuletzt bearbeitet 12.02.2026 20:36:00

OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents based on BlockNote, OpenProject maintainers added a custom extension in OpenProject version 17.0.0 that allows to mention OpenProject ...

  • EPSS 0.02%
  • Veröffentlicht 28.01.2026 18:07:02
  • Zuletzt bearbeitet 12.02.2026 20:41:11

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The OpenPrioject backend generates an authentication token that is current...

  • EPSS 0.06%
  • Veröffentlicht 28.01.2026 16:47:22
  • Zuletzt bearbeitet 09.02.2026 18:24:51

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s repository diff download endpoint (`/projects/:project_id/repository/diff.diff`) whe...

  • EPSS 0.03%
  • Veröffentlicht 19.01.2026 17:52:35
  • Zuletzt bearbeitet 02.02.2026 20:44:39

OpenProject is an open-source, web-based project management software. When using groups in OpenProject to manage users, the group members should only be visible to users that have the View Members permission in any project that the group is also a me...

  • EPSS 0.04%
  • Veröffentlicht 19.01.2026 17:48:03
  • Zuletzt bearbeitet 02.02.2026 20:46:13

OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not...

  • EPSS 0.04%
  • Veröffentlicht 19.01.2026 17:41:41
  • Zuletzt bearbeitet 02.02.2026 20:49:09

OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a stored cross-site scripting vulnerability in the Roadmap view. OpenProject’s roadmap view renders the “Related work packages” list ...