|
401
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44732
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
402
|
5.9 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password…
New
|
CWE-620
Unverified Password Change
|
CVE-2026-44733
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
403
|
9.9 |
CRITICAL
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key.…
New
|
CWE-502 CWE-798 CWE-1188 CWE-1392
Deserialization of Untrusted Data Use of Hard-coded Credentials Insecure Default Initialization of Resource Use of Default Credentials
|
CVE-2026-46386
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
404
|
7.5 |
HIGH
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field vi…
New
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-47193
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
405
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked w…
New
|
CWE-200 CWE-639
Information Exposure Authorization Bypass Through User-Controlled Key
|
CVE-2026-49355
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
406
|
8.6 |
HIGH
Network
|
-
|
-
|
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the …
New
|
CWE-22 CWE-862
Path Traversal Missing Authorization
|
CVE-2026-49991
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
407
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fix…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-52784
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
408
|
9.9 |
CRITICAL
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to …
New
|
CWE-89
SQL Injection
|
CVE-2026-52785
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
409
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details for ALL work packages in a project to any user wit…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44735
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
410
|
5.4 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion in the Calendar and Team Planner modules allows a…
New
|
CWE-639 CWE-863
Authorization Bypass Through User-Controlled Key Incorrect Authorization
|
CVE-2026-52779
|
2026-06-27 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|