Products: 1
Vulnerabilities: 33
Known Exploited: 0
7
Critical Level Threats
5
High Level Threats
19
Medium Level Threats
1
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-55095
OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields
Last Modified: Aug 21, 2026
Published: Aug 20, 2026
CVE-2026-67529
OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)
Last Modified: Jul 31, 2026
Published: Jul 30, 2026
CVE-2026-67528
OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposure
Last Modified: Jul 31, 2026
Published: Jul 30, 2026
CVE-2026-67527
OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"
Last Modified: Jul 31, 2026
Published: Jul 30, 2026
CVE-2026-44733
OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements
Last Modified: Jun 29, 2026
Published: Jun 26, 2026
Items Per Page
