Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openproject
Openproject openproject |
|
| CPEs | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* cpe:2.3:a:openproject:openproject:17.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Openproject
Openproject openproject |
Thu, 19 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opf
Opf openproject |
|
| Vendors & Products |
Opf
Opf openproject |
Wed, 18 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to create commits with filenames that included HTML code that was injected in the page without proper sanitation. This allowed a persisted XSS attack against all members of this project that accessed the repositories page to display a changeset where the maliciously crafted file was deleted. Versions 16.6.9, 17.0.6, 17.1.3, and 17.2.1 fix the issue. | |
| Title | OpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security Policy | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-19T16:14:11.504Z
Reserved: 2026-03-13T14:33:42.823Z
Link: CVE-2026-32703
Updated: 2026-03-19T16:14:05.378Z
Status : Analyzed
Published: 2026-03-18T22:16:24.517
Modified: 2026-03-19T19:23:00.593
Link: CVE-2026-32703
No data.
OpenCVE Enrichment
Updated: 2026-03-19T08:55:26Z