SecAlerts
O

OpenProject

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 54 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from July 26, 2017 to present

54
Total CVEs
25
Critical+High
0
Exploited
18
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
18
Critical/High
Risk Level
42/100
medium
🆕 1Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
10
High
15
Medium
26
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
25

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
7
2
XSS
7
3
SQL Injection
5
4
Command Injection
2
5
CSRF
1

Most Affected Products

1. OpenProject OpenProject100
2. OpenProject openproject/openproject Docker image1
3. npm/op-blocknote-extensions1

Recent Vulnerabilities

See more →
CVE-2026-55095
unknown

OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields

Aug 20, 2026🔧 No Patch
CVE-2026-67529
CVSS 4.3medium

OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)

Jul 30, 2026🔧 No Patch
CVE-2026-67528
CVSS 4.3medium

OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposure

Jul 30, 2026🔧 No Patch
CVE-2026-67527
CVSS 7.6high

OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"

Jul 30, 2026🔧 No Patch
CVE-2026-44731
CVSS 4.3medium

OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosure

Jun 26, 2026🔧 No Patch
CVE-2026-44732
CVSS 4.3medium

OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources

Jun 26, 2026🔧 No Patch
CVE-2026-44734
CVSS 6.5medium

OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename

Jun 26, 2026🔧 No Patch
CVE-2026-44735
CVSS 6.5medium

OpenProject: Shares API Information Disclosure

Jun 26, 2026🔧 No Patch
CVE-2026-44736
CVSS 6.5medium

OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects

Jun 26, 2026🔧 No Patch
CVE-2026-46386
CVSS 9.9critical

OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`

Jun 26, 2026🔧 No Patch

Monitor OpenProject in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.