Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

opf — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting opf. AI-powered Chinese analysis, POCs, and references for each vulnerability.

opf is a software platform primarily utilized for managing and optimizing operational workflows, often serving as a critical infrastructure component in enterprise environments. With thirty-four recorded Common Vulnerabilities and Exposures (CVEs), the system has historically exhibited significant security weaknesses. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, allowing attackers to gain unauthorized access or disrupt service integrity. Notable incidents highlight the severity of these defects, particularly where insufficient input validation led to arbitrary command execution. The accumulation of these CVEs suggests persistent challenges in the development lifecycle regarding secure coding practices and rigorous testing protocols. Organizations relying on opf must prioritize immediate patching and continuous monitoring to mitigate the risk of exploitation, given the platform’s exposure to high-impact attack vectors that compromise both data confidentiality and system availability.

Top products by opf: openproject
CVE IDTitleCVSSSeverityPublished
CVE-2026-44733 OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements — openprojectCWE-620 5.9 Medium2026-06-26
CVE-2026-44731 OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosure — openprojectCWE-639 4.3 Medium2026-06-26
CVE-2026-44732 OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources — openprojectCWE-639 4.3 Medium2026-06-26
CVE-2026-44734 OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename — openprojectCWE-862 6.5 Medium2026-06-26
CVE-2026-44735 OpenProject: Shares API Information Disclosure — openprojectCWE-863 6.5 Medium2026-06-26
CVE-2026-44696 OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltration — openprojectCWE-79 5.7 Medium2026-06-26
CVE-2026-49355 OpenProject: Private work package data disclosure through single meeting agenda item API — openprojectCWE-200 4.3 Medium2026-06-26
CVE-2026-44736 OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects — openprojectCWE-200 6.5 Medium2026-06-26
CVE-2026-46386 OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal` — openprojectCWE-502 9.9 Critical2026-06-26
CVE-2026-52780 OpenProject: Cache store poisoning leads to Remote Code Execution (RCE) — openprojectCWE-20 9.6 Critical2026-06-26
CVE-2026-52779 OpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projects — openprojectCWE-639 5.4 Medium2026-06-26
CVE-2026-47193 OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks — openprojectCWE-200 7.5 High2026-06-26
CVE-2026-52781 OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter "description" — openprojectCWE-79 6.4 Medium2026-06-26
CVE-2026-52782 OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources — openprojectCWE-639 9.9 Critical2026-06-26
CVE-2026-52783 OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others "storage.<id>.httpx_access_token" leads to Sensitive Data Exposure — openprojectCWE-313 8.2 High2026-06-26
CVE-2026-52784 OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]" — openprojectCWE-352 8.8 High2026-06-26
CVE-2026-52785 OpenProject: SQL injection in timestamps functionality — openprojectCWE-89 9.9 Critical2026-06-26
CVE-2026-40896 OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup — openprojectCWE-367 6.5 Medium2026-04-20
CVE-2026-33667 OpenProject: 2FA OTP Verification Missing Rate Limiting — openprojectCWE-307 7.4 High2026-04-15
CVE-2026-34717 OpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_string — openprojectCWE-89 9.9 Critical2026-04-02
CVE-2026-32703 OpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security Policy — openprojectCWE-79 9.1 Critical2026-03-18
CVE-2026-32698 OpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code Execution — openprojectCWE-89 9.1 Critical2026-03-18
CVE-2026-31974 Blind SSRF on OpenProject instance via webhooks — openprojectCWE-918 3.0 Low2026-03-11
CVE-2026-30239 OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets — openprojectCWE-863 6.5 Medium2026-03-11
CVE-2026-30236 OpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rate — openprojectCWE-863 4.3 Medium2026-03-11
CVE-2026-30235 Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobbering — openprojectCWE-79 6.5 Medium2026-03-11
CVE-2026-30234 OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR) — openprojectCWE-22 6.5 Medium2026-03-11
CVE-2026-27723 OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projects — openprojectCWE-284 4.3 Medium2026-03-05
CVE-2026-24777 OpenProject has Improper Access Control on User Management allows user managers to lock admin accounts — openprojectCWE-862 6.7 Medium2026-02-09
CVE-2026-25763 Command Injection on OpenProject repositories leads to Remote Code Execution — openprojectCWE-78 6.5AIMediumAI2026-02-06

This page lists every published CVE security advisory associated with opf. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.