Vulnerabilidades em opf

54 resultados
Análise Vexday

A OPF apresenta 51 vulnerabilidades cadastradas, com 10 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A recente publicação de 17 CVEs nos últimos 90 dias e a predominância de falhas de autorização (CWE-639) indicam um fornecedor em posição de vulnerabilidade elevada, exigindo monitoramento contínuo e atualização prioritária das correções mais recentes.

CVE-2026-30239MEDIUMOpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgetsEPSS 0.2%CVE-2026-32703CRITICALOpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security PolicyEPSS 0.2%CVE-2026-44731MEDIUMOpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosureEPSS 0.2%CVE-2026-52779MEDIUMOpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projectsEPSS 0.2%CVE-2026-23721MEDIUMOpenProject users with "View Members" permission in any project can view all Group membershipsEPSS 0.2%CVE-2026-30236MEDIUMOpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rateEPSS 0.2%CVE-2026-44733MEDIUMOpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirementsEPSS 0.2%CVE-2026-40896MEDIUMOpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section LookupEPSS 0.2%CVE-2026-52784HIGHOpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]"EPSS 0.2%CVE-2026-24772HIGHOpenProject has SSRF and CSWSH in Hocuspocus Synchronization ServerEPSS 0.2%CVE-2026-31974LOWBlind SSRF on OpenProject instance via webhooksEPSS 0.2%CVE-2026-52781MEDIUMOpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter "description"EPSS 0.1%CVE-2026-52783HIGHOpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others "storage.<id>.httpx_access_token" leads to Sensitive Data ExposureEPSS 0.1%CVE-2026-24775MEDIUMOpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor ExtensionEPSS 0.1%