{"schema_version":1,"title":"OpenProject GmbH OpenProject vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in OpenProject GmbH OpenProject: 0 in the last 7 days and 4 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55095, was published on 20 August 2026.","url":"https://junglewise.ai/threats/technologies/openproject","json_url":"https://junglewise.ai/threats/technologies/openproject.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openproject","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":22,"critical":5,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":22},"latest":[{"cve":"CVE-2026-55095","epss":0.004,"slug":"cve-2026-55095-openproject-information-disclosure-in-inplace-edit-dialog","title":"OpenProject information disclosure in inplace-edit dialog","severity":"info","exploited":false,"published_at":"2026-08-20T17:18:24.947+00:00","url":"https://junglewise.ai/threats/cve-2026-55095-openproject-information-disclosure-in-inplace-edit-dialog"},{"cve":"CVE-2026-67529","cvss":4.3,"slug":"cve-2026-67529-openproject-information-disclosure-in-time-and-cost-entry-apis","title":"OpenProject Information Disclosure in Time and Cost Entry APIs","severity":"medium","exploited":false,"published_at":"2026-07-30T20:18:14.75+00:00","url":"https://junglewise.ai/threats/cve-2026-67529-openproject-information-disclosure-in-time-and-cost-entry-apis"},{"cve":"CVE-2026-67528","cvss":4.3,"slug":"cve-2026-67528-openproject-incorrect-authorization-in-custom-options-api","title":"OpenProject incorrect authorization in custom options API","severity":"medium","exploited":false,"published_at":"2026-07-30T20:18:14.613+00:00","url":"https://junglewise.ai/threats/cve-2026-67528-openproject-incorrect-authorization-in-custom-options-api"},{"cve":"CVE-2026-67527","cvss":7.6,"slug":"cve-2026-67527-openproject-missing-authorization-in-work-packages-api-file-links","title":"OpenProject missing authorization in work packages API file links","severity":"high","exploited":false,"published_at":"2026-07-30T20:18:14.473+00:00","url":"https://junglewise.ai/threats/cve-2026-67527-openproject-missing-authorization-in-work-packages-api-file-links"},{"cve":"CVE-2026-52785","cvss":9.9,"slug":"cve-2026-52785-openproject-sql-injection-in-timestamps-functionality","title":"OpenProject SQL injection in timestamps functionality","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:19.133+00:00","url":"https://junglewise.ai/threats/cve-2026-52785-openproject-sql-injection-in-timestamps-functionality"},{"cve":"CVE-2026-52784","cvss":8.8,"slug":"cve-2026-52784-openproject-csrf-privilege-escalation-in-user-management-endpoint","title":"OpenProject CSRF privilege escalation in user management endpoint","severity":"high","exploited":false,"published_at":"2026-06-26T20:17:18.993+00:00","url":"https://junglewise.ai/threats/cve-2026-52784-openproject-csrf-privilege-escalation-in-user-management-endpoint"},{"cve":"CVE-2026-52783","cvss":8.2,"slug":"cve-2026-52783-openproject-cleartext-storage-of-oauth-tokens-in-storages-module","title":"OpenProject cleartext storage of OAuth tokens in Storages module","severity":"high","exploited":false,"published_at":"2026-06-26T20:17:18.86+00:00","url":"https://junglewise.ai/threats/cve-2026-52783-openproject-cleartext-storage-of-oauth-tokens-in-storages-module"},{"cve":"CVE-2026-52782","cvss":9.9,"slug":"cve-2026-52782-openproject-idor-in-project-storage-settings","title":"OpenProject IDOR in project storage settings","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:18.737+00:00","url":"https://junglewise.ai/threats/cve-2026-52782-openproject-idor-in-project-storage-settings"},{"cve":"CVE-2026-52781","cvss":6.4,"slug":"cve-2026-52781-openproject-stored-xss-in-work-package-descriptions","title":"OpenProject stored XSS in work package descriptions","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:18.613+00:00","url":"https://junglewise.ai/threats/cve-2026-52781-openproject-stored-xss-in-work-package-descriptions"},{"cve":"CVE-2026-52780","cvss":9.6,"slug":"cve-2026-52780-openproject-cache-store-poisoning-leads-to-rce","title":"OpenProject cache store poisoning leads to RCE","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:18.49+00:00","url":"https://junglewise.ai/threats/cve-2026-52780-openproject-cache-store-poisoning-leads-to-rce"},{"cve":"CVE-2026-52779","cvss":5.4,"slug":"cve-2026-52779-openproject-idor-in-calendar-and-team-planner-modules","title":"OpenProject IDOR in Calendar and Team Planner modules","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:18.36+00:00","url":"https://junglewise.ai/threats/cve-2026-52779-openproject-idor-in-calendar-and-team-planner-modules"},{"cve":"CVE-2026-49355","cvss":4.3,"slug":"cve-2026-49355-openproject-information-disclosure-in-meeting-agenda-api","title":"OpenProject information disclosure in meeting agenda API","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:17.583+00:00","url":"https://junglewise.ai/threats/cve-2026-49355-openproject-information-disclosure-in-meeting-agenda-api"},{"cve":"CVE-2026-47193","cvss":7.5,"slug":"cve-2026-47193-openproject-information-disclosure-in-journal-diff-endpoint","title":"OpenProject information disclosure in journal diff endpoint","severity":"high","exploited":false,"published_at":"2026-06-26T20:17:13.527+00:00","url":"https://junglewise.ai/threats/cve-2026-47193-openproject-information-disclosure-in-journal-diff-endpoint"},{"cve":"CVE-2026-46386","cvss":9.9,"slug":"cve-2026-46386-openproject-remote-code-execution-via-hardcoded-secret-key-in","title":"OpenProject Remote Code Execution via Hardcoded Secret Key in Docker","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:13.38+00:00","url":"https://junglewise.ai/threats/cve-2026-46386-openproject-remote-code-execution-via-hardcoded-secret-key-in"},{"cve":"CVE-2026-44736","cvss":6.5,"slug":"cve-2026-44736-openproject-information-disclosure-in-relations-api-filter","title":"OpenProject Information Disclosure in Relations API Filter","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:03.657+00:00","url":"https://junglewise.ai/threats/cve-2026-44736-openproject-information-disclosure-in-relations-api-filter"},{"cve":"CVE-2026-44735","cvss":6.5,"slug":"cve-2026-44735-openproject-incorrect-authorization-in-shares-api","title":"OpenProject incorrect authorization in Shares API","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:03.52+00:00","url":"https://junglewise.ai/threats/cve-2026-44735-openproject-incorrect-authorization-in-shares-api"},{"cve":"CVE-2026-44734","cvss":6.5,"slug":"cve-2026-44734-openproject-missing-authorization-in-costreportscontroller","title":"OpenProject missing authorization in CostReportsController","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:03.377+00:00","url":"https://junglewise.ai/threats/cve-2026-44734-openproject-missing-authorization-in-costreportscontroller"},{"cve":"CVE-2026-44733","cvss":5.9,"slug":"cve-2026-44733-openproject-unverified-password-change-in-users-api","title":"OpenProject unverified password change in users API","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:03.24+00:00","url":"https://junglewise.ai/threats/cve-2026-44733-openproject-unverified-password-change-in-users-api"},{"cve":"CVE-2026-44732","cvss":4.3,"slug":"cve-2026-44732-openproject-authorization-bypass-in-document-update-endpoint","title":"OpenProject authorization bypass in document update endpoint","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:03.093+00:00","url":"https://junglewise.ai/threats/cve-2026-44732-openproject-authorization-bypass-in-document-update-endpoint"},{"cve":"CVE-2026-44731","cvss":4.3,"slug":"cve-2026-44731-openproject-user-enumeration-and-name-disclosure-in-meetings","title":"OpenProject user enumeration and name disclosure in meetings filter","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:02.943+00:00","url":"https://junglewise.ai/threats/cve-2026-44731-openproject-user-enumeration-and-name-disclosure-in-meetings"},{"cve":"CVE-2026-44696","cvss":5.7,"slug":"cve-2026-44696-openproject-stored-css-injection-in-markdown-rendering-pipeline","title":"OpenProject stored CSS injection in markdown rendering pipeline","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:02.793+00:00","url":"https://junglewise.ai/threats/cve-2026-44696-openproject-stored-css-injection-in-markdown-rendering-pipeline"},{"cve":"CVE-2026-34717","cvss":9.9,"epss":0.0027,"slug":"cve-2026-34717-openproject-sql-injection-in-cost-reporting-module","title":"OpenProject SQL injection in Cost Reporting module","severity":"critical","exploited":false,"published_at":"2026-04-02T18:16:33.083+00:00","url":"https://junglewise.ai/threats/cve-2026-34717-openproject-sql-injection-in-cost-reporting-module"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"OpenProject GmbH OpenProject","slug":"openproject","vendor":{"name":"OpenProject GmbH","slug":"openproject-gmbh","url":"https://junglewise.ai/threats/vendors/openproject-gmbh"},"aliases":[],"category":"project-management-software","homepage":"https://www.openproject.org/","repo_url":"https://github.com/opf/openproject","description":"OpenProject is an open-source project management software for collaboration, project planning, and team communication.","url":"https://junglewise.ai/threats/technologies/openproject"},"most_severe":[{"cve":"CVE-2026-34717","cvss":9.9,"epss":0.0027,"slug":"cve-2026-34717-openproject-sql-injection-in-cost-reporting-module","title":"OpenProject SQL injection in Cost Reporting module","severity":"critical","exploited":false,"published_at":"2026-04-02T18:16:33.083+00:00","url":"https://junglewise.ai/threats/cve-2026-34717-openproject-sql-injection-in-cost-reporting-module"},{"cve":"CVE-2026-52785","cvss":9.9,"slug":"cve-2026-52785-openproject-sql-injection-in-timestamps-functionality","title":"OpenProject SQL injection in timestamps functionality","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:19.133+00:00","url":"https://junglewise.ai/threats/cve-2026-52785-openproject-sql-injection-in-timestamps-functionality"},{"cve":"CVE-2026-52782","cvss":9.9,"slug":"cve-2026-52782-openproject-idor-in-project-storage-settings","title":"OpenProject IDOR in project storage settings","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:18.737+00:00","url":"https://junglewise.ai/threats/cve-2026-52782-openproject-idor-in-project-storage-settings"},{"cve":"CVE-2026-46386","cvss":9.9,"slug":"cve-2026-46386-openproject-remote-code-execution-via-hardcoded-secret-key-in","title":"OpenProject Remote Code Execution via Hardcoded Secret Key in Docker","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:13.38+00:00","url":"https://junglewise.ai/threats/cve-2026-46386-openproject-remote-code-execution-via-hardcoded-secret-key-in"},{"cve":"CVE-2026-52780","cvss":9.6,"slug":"cve-2026-52780-openproject-cache-store-poisoning-leads-to-rce","title":"OpenProject cache store poisoning leads to RCE","severity":"critical","exploited":false,"published_at":"2026-06-26T20:17:18.49+00:00","url":"https://junglewise.ai/threats/cve-2026-52780-openproject-cache-store-poisoning-leads-to-rce"},{"cve":"CVE-2026-52784","cvss":8.8,"slug":"cve-2026-52784-openproject-csrf-privilege-escalation-in-user-management-endpoint","title":"OpenProject CSRF privilege escalation in user management endpoint","severity":"high","exploited":false,"published_at":"2026-06-26T20:17:18.993+00:00","url":"https://junglewise.ai/threats/cve-2026-52784-openproject-csrf-privilege-escalation-in-user-management-endpoint"},{"cve":"CVE-2026-52783","cvss":8.2,"slug":"cve-2026-52783-openproject-cleartext-storage-of-oauth-tokens-in-storages-module","title":"OpenProject cleartext storage of OAuth tokens in Storages module","severity":"high","exploited":false,"published_at":"2026-06-26T20:17:18.86+00:00","url":"https://junglewise.ai/threats/cve-2026-52783-openproject-cleartext-storage-of-oauth-tokens-in-storages-module"},{"cve":"CVE-2026-67527","cvss":7.6,"slug":"cve-2026-67527-openproject-missing-authorization-in-work-packages-api-file-links","title":"OpenProject missing authorization in work packages API file links","severity":"high","exploited":false,"published_at":"2026-07-30T20:18:14.473+00:00","url":"https://junglewise.ai/threats/cve-2026-67527-openproject-missing-authorization-in-work-packages-api-file-links"},{"cve":"CVE-2026-47193","cvss":7.5,"slug":"cve-2026-47193-openproject-information-disclosure-in-journal-diff-endpoint","title":"OpenProject information disclosure in journal diff endpoint","severity":"high","exploited":false,"published_at":"2026-06-26T20:17:13.527+00:00","url":"https://junglewise.ai/threats/cve-2026-47193-openproject-information-disclosure-in-journal-diff-endpoint"},{"cve":"CVE-2026-44736","cvss":6.5,"slug":"cve-2026-44736-openproject-information-disclosure-in-relations-api-filter","title":"OpenProject Information Disclosure in Relations API Filter","severity":"medium","exploited":false,"published_at":"2026-06-26T20:17:03.657+00:00","url":"https://junglewise.ai/threats/cve-2026-44736-openproject-information-disclosure-in-relations-api-filter"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}