CVE-2026-40896
- EPSS 0.17%
- Veröffentlicht 20.04.2026 15:12:52
- Zuletzt bearbeitet 23.04.2026 13:45:17
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project can inject agenda items into meetings belonging to any other project on the instance — even projects th...
CVE-2026-33667
- EPSS 0.3%
- Veröffentlicht 15.04.2026 18:43:14
- Zuletzt bearbeitet 28.04.2026 15:59:24
OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The...
CVE-2026-34717
- EPSS 0.27%
- Veröffentlicht 02.04.2026 17:59:55
- Zuletzt bearbeitet 21.04.2026 01:03:32
OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE clauses without parameterization. This issue has ...
CVE-2026-32703
- EPSS 0.19%
- Veröffentlicht 18.03.2026 21:04:16
- Zuletzt bearbeitet 19.03.2026 19:23:00
OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push a...
CVE-2026-32698
- EPSS 0.27%
- Veröffentlicht 18.03.2026 21:01:53
- Zuletzt bearbeitet 19.03.2026 18:32:37
OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the cust...
CVE-2026-31974
- EPSS 0.16%
- Veröffentlicht 11.03.2026 19:39:25
- Zuletzt bearbeitet 23.03.2026 14:25:54
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (POST /admin/settings/mail_notifications) accepts arbitrary host and port values and exhibits measurable differences in response beh...
CVE-2026-30239
- EPSS 0.19%
- Veröffentlicht 11.03.2026 16:27:31
- Zuletzt bearbeitet 13.03.2026 19:01:28
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permissi...
CVE-2026-30236
- EPSS 0.18%
- Veröffentlicht 11.03.2026 16:25:07
- Zuletzt bearbeitet 13.03.2026 19:02:34
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked that the user that was planned in the budget is actually a project member. This expos...
CVE-2026-30234
- EPSS 0.3%
- Veröffentlicht 11.03.2026 16:16:41
- Zuletzt bearbeitet 17.03.2026 15:53:21
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the <Snapshot> value in markup.bcf is manipulated to contain an...
CVE-2026-30235
- EPSS 0.32%
- Veröffentlicht 11.03.2026 16:06:43
- Zuletzt bearbeitet 13.03.2026 19:22:16
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenProject’s Markdown rendering, specifically in the hyperlink handling. This allows an attacker to inject...