📦 Openproject

by Openproject

🔍 What is Openproject?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25763

CRITICAL CVSS 9.9 Feb 6, 2026

OpenProject versions before 16.6.7 and 17.0.3 contain an arbitrary file write vulnerability that can lead to remote code execution. Attackers with repository browsing permissions can inject git log op...

CVE-2026-24772

HIGH CVSS 8.9 Jan 28, 2026

OpenProject's synchronization server improperly validates backend URLs, allowing attackers to decrypt intercepted authentication tokens and gain unauthorized access to user accounts. This affects Open...

CVE-2026-24685

HIGH CVSS 8.8 Jan 28, 2026

OpenProject versions before 16.6.6 and 17.0.2 have a command injection vulnerability that allows authenticated users with repository browsing permissions to write arbitrary files. Attackers can inject...

CVE-2026-23625

HIGH CVSS 8.7 Jan 19, 2026

OpenProject versions 16.3.0 through 16.6.4 have a stored cross-site scripting vulnerability in the Roadmap view that allows attackers to inject malicious HTML/JavaScript via subproject names. This aff...

CVE-2024-35224

HIGH CVSS 7.6 May 23, 2024

This vulnerability allows stored cross-site scripting (XSS) in OpenProject's Cost Report feature via misconfigured tablesorter dependency. Attackers with 'Edit work packages' and 'Add attachments' per...

CVE-2023-33960

HIGH CVSS 7.5 Jun 1, 2023

OpenProject's robots.txt file publicly exposes project identifiers even when the entire instance is configured to require login. This information disclosure vulnerability affects all OpenProject insta...

CVE-2026-24777

MEDIUM CVSS 6.7 Feb 9, 2026

OpenProject versions before 17.0.2 contain a missing authorization vulnerability where users with 'Manage Users' permission can lock application administrators, which should be restricted. This allows...

CVE-2026-24776

MEDIUM CVSS 4.3 Feb 6, 2026

This vulnerability in OpenProject allows authenticated attackers to move meeting agenda items into different meetings they shouldn't have access to, potentially causing confusion by adding arbitrary a...

CVE-2026-24775

MEDIUM CVSS 6.3 Jan 28, 2026

OpenProject versions 17.0.0-17.0.1 contain a server-side request forgery (SSRF) vulnerability in the collaborative document editor. Attackers can craft documents with malicious work package IDs that t...

CVE-2026-23646

MEDIUM CVSS 6.5 Jan 19, 2026

OpenProject versions before 16.6.5 and 17.0.1 contain a session management vulnerability where users can delete other users' active sessions. This allows authenticated users to forcibly log out other ...

CVE-2026-23721

MEDIUM CVSS 4.3 Jan 19, 2026

OpenProject versions before 17.0.1 and 16.6.5 have an information disclosure vulnerability where users with View Members permission in any project can enumerate all groups and see their members. This ...

CVE-2024-41801

MEDIUM CVSS 4.7 Jul 25, 2024

OpenProject versions before 14.3.0 are vulnerable to host header injection, allowing attackers to forge HOST headers to redirect users to malicious sites for phishing attacks. This affects default pac...

CVE-2026-25764

LOW CVSS 3.5 Feb 6, 2026

OpenProject versions before 16.6.7 and 17.0.3 contain an HTML injection vulnerability in the time tracking function. An attacker with administrator privileges can inject HTML tags into work package na...