github.comConfirmation
https://github.com/opf/openproject/security/advisories/GHSA-98vw-2r87-fx2r CVE-2026-52785
CRITICAL
OpenProject: SQL injection in timestamps functionality
Record summary
CVE-2026-52785 has a selected CVSS score of 9.9 (critical).
Description
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This vulnerability is fixed in 17.3.3 and 17.4.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 29, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
openprojectBrowse opf / openproject | CVE List | < 17.3.3 | affected |
| >= 17.4.0, < 17.4.1 | affected |