Skip to content
Noroxi

openproject records

37 published records for vendor openproject.

All records

37 records
  • A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands v

    HighCVSS 8.1Proof of conceptEPSS 80%

    openproject · openprojectMay 13, 2019

  • Command Injection on OpenProject repositories leads to Remote Code Execution

    CriticalCVSS 9.4No exploitEPSS 1%

    openproject · openprojectFeb 6, 2026

  • OpenProject has Argument Injection on Repository module that allows Arbitrary File Write

    CriticalCVSS 9.4No exploitEPSS 0%

    openproject · openprojectJan 28, 2026

  • OpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG Coder

    CriticalCVSS 9.1No exploitEPSS 0%

    openproject · openprojectJan 9, 2026

  • OpenProject has SSRF and CSWSH in Hocuspocus Synchronization Server

    CriticalCVSS 9.0No exploitEPSS 0%

    openproject · openprojectJan 28, 2026

  • SQL injection in OpenProject

    HighCVSS 8.8No exploitEPSS 1%

    openproject · openprojectDec 14, 2021

  • OpenProject is Vulnerable to Code Execution in E-Mail function

    HighCVSS 8.6No exploitEPSS 0%

    openproject · openprojectJan 9, 2026

  • OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitel

    HighCVSS 8.1No exploitEPSS 1%

    openproject · openprojectJul 26, 2017

  • OpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_string

    HighCVSS 8.1No exploitEPSS 0%

    openproject · openprojectApr 2, 2026

  • OpenProject vulnerable to project identifier information leakage through robots.txt

    HighCVSS 7.5Proof of conceptEPSS 1%

    openproject · openprojectJun 1, 2023

  • OpenProject: 2FA OTP Verification Missing Rate Limiting

    HighCVSS 7.4No exploitEPSS 0%

    openproject · openprojectApr 15, 2026

  • OpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor Extension

    HighCVSS 7.3No exploitEPSS 0%

    openproject · openprojectJan 28, 2026

  • OpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code Execution

    HighCVSS 7.2No exploitEPSS 0%

    openproject · openprojectMar 18, 2026

  • OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets

    HighCVSS 7.1No exploitEPSS 0%

    openproject · openprojectMar 11, 2026

  • OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup

    HighCVSS 7.1No exploitEPSS 0%

    openproject · openprojectApr 20, 2026

  • OpenProject is vulnerable to user enumeration via the change password function

    MediumCVSS 6.9No exploitEPSS 0%

    openproject · openprojectJan 9, 2026

  • OpenProject has no protection against brute-force attacks in the Change Password function

    MediumCVSS 6.9No exploitEPSS 0%

    openproject · openprojectJan 9, 2026

  • Regular Expression Denial of Service in OpenProject forum messages

    MediumCVSS 6.5No exploitEPSS 1%

    openproject · openprojectJul 20, 2021

  • OpenProject user sessions not terminated after activation of 2FA

    MediumCVSS 6.5No exploitEPSS 1%

    openproject · openprojectMay 8, 2023

  • Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobbering

    MediumCVSS 6.5No exploitEPSS 1%

    openproject · openprojectMar 11, 2026

  • OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR)

    MediumCVSS 6.5No exploitEPSS 0%

    openproject · openprojectMar 11, 2026

  • OpenProject users can delete other user's session, causing them to be logged out

    MediumCVSS 6.5No exploitEPSS 0%

    openproject · openprojectJan 19, 2026

  • OpenProject has Improper Access Control on User Management allows user managers to lock admin accounts

    MediumCVSS 6.7No exploitEPSS 0%

    openproject · openprojectFeb 9, 2026

  • An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web scri

    MediumCVSS 6.1No exploitEPSS 2%

    openproject · openprojectOct 9, 2019

  • OpenProject packaged installation has Open Redirect Vulnerability in Sign-In in default configuration

    MediumCVSS 6.1No exploitEPSS 0%

    openproject · openprojectJul 25, 2024