15 Total CVEs
15 AI Analyzed
0 CISA KEV
8 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
53% rated critical (CVSS 9.0+) 8 critical, 7 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • OpenProject9
  • openproject2

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-67527
Analyzed
7.6
opf OpenProject

OpenProject is open-source, web-based project management software

2026-08-01
CVE-2026-52785
Analyzed
9.9
opf openproject

OpenProject contains a SQL injection vulnerability in the timestamps functionality, allowing authenticated attackers to execute arbitrary SQL queries...

2026-06-27
CVE-2026-52784
Analyzed
8.8
opf OpenProject

OpenProject is open-source, web-based project management software

2026-06-27
CVE-2026-52783
Analyzed
8.2
opf OpenProject

OpenProject is open-source, web-based project management software

2026-06-27
CVE-2026-52782
Analyzed
9.9
opf openproject

OpenProject contains an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated project administrators to hijack project folde...

2026-06-27
CVE-2026-52780
Analyzed
9.6
opf OpenProject

OpenProject is vulnerable to cache store poisoning, which can be leveraged by attackers to achieve Remote Code Execution on the host system.

2026-06-27
CVE-2026-47193
Analyzed
7.5
opf OpenProject

OpenProject is open-source, web-based project management software

2026-06-28
CVE-2026-46386
Analyzed
9.9
opf OpenProject

A default, insecure secret key configuration in the official OpenProject Docker image allows authenticated users to achieve remote code execution via...

2026-06-27
CVE-2026-34717
Analyzed
9.9
opf OpenProject

A SQL injection vulnerability in OpenProject's reporting module allows attackers to execute unauthorized database queries via unparameterized user inp...

2026-04-03
CVE-2026-33667
Analyzed
7.4
opf Multiple Products

OpenProject is an open-source project management application

2026-04-17
CVE-2026-32703
Analyzed
9
opf OpenProject

The OpenProject Repositories module is vulnerable to a persisted Cross-Site Scripting (XSS) attack due to improper sanitation of filenames within repo...

2026-03-19
CVE-2026-32698
Analyzed
9.1
opf OpenProject

OpenProject is vulnerable to an SQL injection via custom field names, which can be leveraged to manipulate git checkout paths and achieve arbitrary Ru...

2026-03-19
CVE-2026-24772
Analyzed
8.9
opf Multiple Products

OpenProject is an open-source, web-based project management software

2026-01-29
CVE-2026-23625
Analyzed
8.7
opf Multiple Products

OpenProject is an open-source, web-based project management software

2026-01-20
CVE-2026-22600
Analyzed
9.1
opf Multiple Products

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export func...

2026-01-10