CVE-2026-34717
- EPSS 0.05%
- Veröffentlicht 02.04.2026 17:59:55
- Zuletzt bearbeitet 21.04.2026 01:03:32
OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE clauses without parameterization. This issue has ...
CVE-2026-32703
- EPSS 0.04%
- Veröffentlicht 18.03.2026 21:04:16
- Zuletzt bearbeitet 19.03.2026 19:23:00
OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push a...
CVE-2026-32698
- EPSS 0.04%
- Veröffentlicht 18.03.2026 21:01:53
- Zuletzt bearbeitet 19.03.2026 18:32:37
OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the cust...
CVE-2026-31974
- EPSS 0.03%
- Veröffentlicht 11.03.2026 19:39:25
- Zuletzt bearbeitet 23.03.2026 14:25:54
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (POST /admin/settings/mail_notifications) accepts arbitrary host and port values and exhibits measurable differences in response beh...
CVE-2026-30239
- EPSS 0.04%
- Veröffentlicht 11.03.2026 16:27:31
- Zuletzt bearbeitet 13.03.2026 19:01:28
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permissi...
CVE-2026-30236
- EPSS 0.03%
- Veröffentlicht 11.03.2026 16:25:07
- Zuletzt bearbeitet 13.03.2026 19:02:34
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked that the user that was planned in the budget is actually a project member. This expos...
CVE-2026-30234
- EPSS 0.05%
- Veröffentlicht 11.03.2026 16:16:41
- Zuletzt bearbeitet 17.03.2026 15:53:21
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the <Snapshot> value in markup.bcf is manipulated to contain an...
CVE-2026-30235
- EPSS 0.09%
- Veröffentlicht 11.03.2026 16:06:43
- Zuletzt bearbeitet 13.03.2026 19:22:16
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenProject’s Markdown rendering, specifically in the hyperlink handling. This allows an attacker to inject...
CVE-2026-27723
- EPSS 0.04%
- Veröffentlicht 05.03.2026 16:26:39
- Zuletzt bearbeitet 10.03.2026 18:21:31
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been patched in...
CVE-2026-24777
- EPSS 0.06%
- Veröffentlicht 09.02.2026 18:28:45
- Zuletzt bearbeitet 11.02.2026 18:28:40
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock users. This functionality should only be possible for users of the application, but they were not suppos...