CVE Feed

    Dashboard / CVE / CVE-2026-25764

    CVE-2026-25764

    OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The application does not escape HTML tags, an attacker with administrator privileges can create a work package with the name containing the HTML tags and add it to the Work package section when creating time tracking. This issue has been patched in versions 16.6.7 and 17.0.3.

    Published:Feb 6, 2026
    Last Modified:Apr 17, 2026
    EPS:Feb 6, 2026
    EPSS Score:0.00023
    CVSS Score:3.5

    Affected Products

    Vendor
    Openproject
    Product
    Openproject

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High