Products: 1
    Vulnerabilities: 33
    Known Exploited: 0
    7
    Critical Level Threats
    5
    High Level Threats
    19
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-55095

    OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields

    Last Modified: Aug 21, 2026
    Published: Aug 20, 2026

    CVE-2026-67529

    OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)

    Last Modified: Jul 31, 2026
    Published: Jul 30, 2026

    CVE-2026-67528

    OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposure

    Last Modified: Jul 31, 2026
    Published: Jul 30, 2026

    CVE-2026-67527

    OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"

    Last Modified: Jul 31, 2026
    Published: Jul 30, 2026

    CVE-2026-44733

    OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements

    Last Modified: Jun 29, 2026
    Published: Jun 26, 2026
    Items Per Page
    Opf Vulnerabilities & Security CVEs | CVE-DB