Ad

CVE-2026-32703

CRITICAL CVSS 3.1: 5.4 EPSS 0.03%
Updated Mar 19, 2026
Openproject
Parameter Value
CVSS 5.4 (CRITICAL)
Affected Versions 17.0.0 — 17.1.3
Fixed In 16.6.9
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Openproject
Public PoC No

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to create commits with filenames that included HTML code that was injected in the page without proper sanitation.

This allowed a persisted XSS attack against all members of this project that accessed the repositories page to display a changeset where the maliciously crafted file was deleted. Versions 16.6.9, 17.0.6, 17.1.3, and 17.2.1 fix the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 4

Configuration From (including) Up to (excluding)
Openproject Openproject
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*
16.6.9
Openproject Openproject
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*
17.0.0 17.0.6
Openproject Openproject
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*
17.1.0 17.1.3
Openproject Openproject
cpe:2.3:a:openproject:openproject:17.2.0:*:*:*:*:*:*:*