Vulnerabilidades en opf

54 resultados
Análisis Vexday

A OPF apresenta 51 vulnerabilidades cadastradas, com 10 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A recente publicação de 17 CVEs nos últimos 90 dias e a predominância de falhas de autorização (CWE-639) indicam um fornecedor em posição de vulnerabilidade elevada, exigindo monitoramento contínuo e atualização prioritária das correções mais recentes.

CVE-2026-32698CRITICALOpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code ExecutionEPSS 0.3%CVE-2026-22602LOWOpenProject is Vulnerable to User Enumeration via User IDEPSS 0.3%CVE-2026-22604MEDIUMOpenProject is vulnerable to user enumeration via the change password functionEPSS 0.3%CVE-2026-52782CRITICALOpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized ResourcesEPSS 0.3%CVE-2026-47193HIGHOpenProject: Journal diff endpoint bypasses object, journal, and field visibility checksEPSS 0.3%CVE-2026-67527HIGHOpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"EPSS 0.2%CVE-2026-25764LOWOpenProject vulnerable to Stored HTML injectionEPSS 0.2%CVE-2026-67529MEDIUMOpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)EPSS 0.2%CVE-2026-44734MEDIUMOpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/renameEPSS 0.2%CVE-2026-52780CRITICALOpenProject: Cache store poisoning leads to Remote Code Execution (RCE)EPSS 0.2%CVE-2026-22603MEDIUMOpenProject has no protection against brute-force attacks in the Change Password functionEPSS 0.2%CVE-2026-52785CRITICALOpenProject: SQL injection in timestamps functionalityEPSS 0.2%CVE-2026-49355MEDIUMOpenProject: Private work package data disclosure through single meeting agenda item APIEPSS 0.2%CVE-2026-44696MEDIUMOpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltrationEPSS 0.2%CVE-2026-67528MEDIUMOpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data ExposureEPSS 0.2%CVE-2026-27723MEDIUMOpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projectsEPSS 0.2%CVE-2026-23625HIGHOpenProject has stored XSS regression using attachments and script-src selfEPSS 0.2%CVE-2026-22605MEDIUMOpenProject is Vulnerable to Insecure Direct Object Reference in MeetingsEPSS 0.2%CVE-2026-44732MEDIUMOpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of ResourcesEPSS 0.2%CVE-2026-24776MEDIUMOpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transferEPSS 0.2%