Vulnerabilidades en opf

55 resultados
Análisis Vexday

A OPF apresenta 51 vulnerabilidades cadastradas, com 10 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A recente publicação de 17 CVEs nos últimos 90 dias e a predominância de falhas de autorização (CWE-639) indicam um fornecedor em posição de vulnerabilidade elevada, exigindo monitoramento contínuo e atualização prioritária das correções mais recentes.

CVE-2023-33960HIGHOpenProject vulnerable to project identifier information leakage through robots.txtEPSS 1.3%CVE-2021-43830HIGHSQL injection in OpenProjectEPSS 0.9%CVE-2021-32763MEDIUMRegular Expression Denial of Service in OpenProject forum messagesEPSS 0.9%CVE-2023-31140MEDIUMOpenProject user sessions not terminated after activation of 2FAEPSS 0.9%CVE-2026-25763CRITICALCommand Injection on OpenProject repositories leads to Remote Code ExecutionEPSS 0.7%CVE-2026-30235MEDIUMBusiness Logic Error on OpenProject through hyperlinks in markdown using DOM clobberingEPSS 0.6%CVE-2026-46386CRITICALOpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`EPSS 0.5%CVE-2026-52782CRITICALOpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized ResourcesEPSS 0.5%CVE-2026-30234MEDIUMOpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR)EPSS 0.5%CVE-2026-34717CRITICALOpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_stringEPSS 0.4%CVE-2026-32698CRITICALOpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code ExecutionEPSS 0.4%CVE-2026-67527HIGHOpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"EPSS 0.4%CVE-2026-47193HIGHOpenProject: Journal diff endpoint bypasses object, journal, and field visibility checksEPSS 0.4%CVE-2026-67529MEDIUMOpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)EPSS 0.4%CVE-2026-33667HIGHOpenProject: 2FA OTP Verification Missing Rate LimitingEPSS 0.4%CVE-2026-55095MEDIUMOpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fieldsEPSS 0.4%CVE-2026-44736MEDIUMOpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package SubjectsEPSS 0.4%CVE-2026-52780CRITICALOpenProject: Cache store poisoning leads to Remote Code Execution (RCE)EPSS 0.4%CVE-2026-52785CRITICALOpenProject: SQL injection in timestamps functionalityEPSS 0.4%CVE-2026-44735MEDIUMOpenProject: Shares API Information DisclosureEPSS 0.4%