Vulnerabilidades en opf
55 resultadosAnálisis Vexday
A OPF apresenta 51 vulnerabilidades cadastradas, com 10 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A recente publicação de 17 CVEs nos últimos 90 dias e a predominância de falhas de autorização (CWE-639) indicam um fornecedor em posição de vulnerabilidade elevada, exigindo monitoramento contínuo e atualização prioritária das correções mais recentes.
CVE-2026-22602LOWOpenProject is Vulnerable to User Enumeration via User IDEPSS 0.3%CVE-2026-44733MEDIUMOpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirementsEPSS 0.3%CVE-2026-44732MEDIUMOpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of ResourcesEPSS 0.3%CVE-2026-31974LOWBlind SSRF on OpenProject instance via webhooksEPSS 0.3%CVE-2026-22603MEDIUMOpenProject has no protection against brute-force attacks in the Change Password functionEPSS 0.3%CVE-2026-52781MEDIUMOpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter "description"EPSS 0.3%CVE-2026-23625HIGHOpenProject has stored XSS regression using attachments and script-src selfEPSS 0.2%CVE-2026-52784HIGHOpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]"EPSS 0.2%CVE-2026-40896MEDIUMOpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section LookupEPSS 0.2%CVE-2026-22605MEDIUMOpenProject is Vulnerable to Insecure Direct Object Reference in MeetingsEPSS 0.2%CVE-2026-23721MEDIUMOpenProject users with "View Members" permission in any project can view all Group membershipsEPSS 0.2%CVE-2026-52783HIGHOpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others "storage.<id>.httpx_access_token" leads to Sensitive Data ExposureEPSS 0.2%CVE-2026-24776MEDIUMOpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transferEPSS 0.2%CVE-2026-24772HIGHOpenProject has SSRF and CSWSH in Hocuspocus Synchronization ServerEPSS 0.2%CVE-2026-24775MEDIUMOpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor ExtensionEPSS 0.1%