Openproject is a web-based project management and collaboration platform whose vulnerability profile concentrates in a single widely deployed application. The vendor's disclosures recur through application-layer weakness classes including cross-site scripting, SQL injection, authorization bypass, and improper access control, reflecting the authentication, input handling, and data-access demands of a multi-tenant web service. A meaningful share of vulnerabilities acquire public exploit code, and the recurring pattern of authorization and access-control flaws creates material risk for environments where the platform manages sensitive project data and team credentials. Defenders should monitor this vendor's release cycle and prioritize patching for internet-exposed instances, particularly around authentication boundaries; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openproject over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11600HIGH A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be p | May 13, 2019 | 8.1 | 79 | NO | YES |
CVE-2026-22600CRITICAL OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior | Jan 10, 2026 | 9.1 | 33 | NO | NO |
CVE-2023-33960HIGH OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall no | Jun 1, 2023 | 7.5 | 33 | NO | YES |
CVE-2026-25763CRITICAL OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository | Feb 6, 2026 | 9.9 | 32 | NO | NO |
CVE-2026-24772CRITICAL OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The | Jan 28, 2026 | 9.0 | 29 | NO | NO |
CVE-2026-24685HIGH OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s repository dif | Jan 28, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-34717HIGH OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input dir | Apr 2, 2026 | 8.1 | 28 | NO | NO |
CVE-2021-43830HIGH OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Ed | Dec 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2017-11667HIGH OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session. | Jul 26, 2017 | 8.1 | 26 | NO | NO |
CVE-2026-32698HIGH OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom fi | Mar 18, 2026 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openproject.
Media articles that mention a CVE ID that affects a product developed by Openproject — matched by CVE ID, not by vendor name.