Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-52785: OpenProject: Unsecured Timestamps in Project Management Software

CVE-2026-52785
Summary

OpenProject's project management software had a security weakness that could have allowed hackers to access sensitive information. This weakness has been fixed in versions 17.3.3 and 17.4.1, so users should update to these versions to stay secure.

Original title
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers t...
Original description
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This vulnerability is fixed in 17.3.3 and 17.4.1.
nvd CVSS3.1 9.9
Vulnerability type
CWE-89 SQL Injection
Published: 26 Jun 2026 · Updated: 20 Jul 2026 · First seen: 26 Jun 2026