Vulnerabilidades em opf

55 resultados
Análise Vexday

A OPF apresenta 51 vulnerabilidades cadastradas, com 10 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A recente publicação de 17 CVEs nos últimos 90 dias e a predominância de falhas de autorização (CWE-639) indicam um fornecedor em posição de vulnerabilidade elevada, exigindo monitoramento contínuo e atualização prioritária das correções mais recentes.

CVE-2026-22601HIGHOpenProject is Vulnerable to Code Execution in E-Mail functionEPSS 0.4%CVE-2026-23646MEDIUMOpenProject users can delete other user's session, causing them to be logged outEPSS 0.4%CVE-2026-67528MEDIUMOpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data ExposureEPSS 0.4%CVE-2026-27723MEDIUMOpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projectsEPSS 0.4%CVE-2026-25764LOWOpenProject vulnerable to Stored HTML injectionEPSS 0.4%CVE-2024-41801MEDIUMOpenProject packaged installation has Open Redirect Vulnerability in Sign-In in default configurationEPSS 0.3%CVE-2026-24777MEDIUMOpenProject has Improper Access Control on User Management allows user managers to lock admin accountsEPSS 0.3%CVE-2026-24685CRITICALOpenProject has Argument Injection on Repository module that allows Arbitrary File WriteEPSS 0.3%CVE-2024-35224HIGHStored Cross-Site Scripting (XSS) in OpenProjectEPSS 0.3%CVE-2026-44734MEDIUMOpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/renameEPSS 0.3%CVE-2026-30239MEDIUMOpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgetsEPSS 0.3%CVE-2026-32703CRITICALOpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security PolicyEPSS 0.3%CVE-2026-52779MEDIUMOpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projectsEPSS 0.3%CVE-2026-22600CRITICALOpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG CoderEPSS 0.3%CVE-2026-44696MEDIUMOpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltrationEPSS 0.3%CVE-2026-22604MEDIUMOpenProject is vulnerable to user enumeration via the change password functionEPSS 0.3%CVE-2025-24892LOWOpenProject stored HTML injection vulnerabilityEPSS 0.3%CVE-2026-44731MEDIUMOpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosureEPSS 0.3%CVE-2026-30236MEDIUMOpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rateEPSS 0.3%CVE-2026-49355MEDIUMOpenProject: Private work package data disclosure through single meeting agenda item APIEPSS 0.3%