Openproject

Openproject

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 10.01.2026 01:07:10
  • Zuletzt bearbeitet 14.01.2026 22:27:55

OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the u...

  • EPSS 0.04%
  • Veröffentlicht 10.01.2026 01:07:02
  • Zuletzt bearbeitet 14.01.2026 22:27:23

OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST request to the /account/change_password endpoint with an arbitrary User ID as the password_change_user_id...

  • EPSS 0.04%
  • Veröffentlicht 10.01.2026 01:06:28
  • Zuletzt bearbeitet 14.01.2026 22:27:03

OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint (/account/change_password) was not protected by the same brute-force safeguards that apply to the no...

  • EPSS 0.01%
  • Veröffentlicht 10.01.2026 01:06:12
  • Zuletzt bearbeitet 14.01.2026 22:26:18

OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-in user can view the full names of other users. Since user IDs are assigned sequentially and predictably (e.g., 1 to 1000), an atta...

  • EPSS 0.08%
  • Veröffentlicht 10.01.2026 01:06:05
  • Zuletzt bearbeitet 14.01.2026 22:26:03

OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execute arbitrary command by configuring sendmail binary path and sending a test email. This issue has been...

  • EPSS 0.02%
  • Veröffentlicht 10.01.2026 01:06:00
  • Zuletzt bearbeitet 14.01.2026 22:25:56

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguis...

  • EPSS 0.34%
  • Veröffentlicht 10.02.2025 16:15:39
  • Zuletzt bearbeitet 27.08.2025 02:09:35

OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not p...

  • EPSS 0.34%
  • Veröffentlicht 25.07.2024 17:15:11
  • Zuletzt bearbeitet 21.11.2024 09:33:05

OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged installations and using the "Login required" setting, an attacker could redirect to a remote host to ...

  • EPSS 0.21%
  • Veröffentlicht 23.05.2024 13:15:09
  • Zuletzt bearbeitet 13.02.2026 15:44:32

OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header values. Th...

  • EPSS 39.69%
  • Veröffentlicht 01.06.2023 17:15:10
  • Zuletzt bearbeitet 21.11.2024 08:06:17

OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall not be accessed by crawlers. These routes contain project identifiers of...