
CVE-2026-25764 OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking… https://www.cve.org/CVERecord?id=CVE-2026-25764
Post summary
CVE‑2026‑25764 is an HTML injection flaw in OpenProject’s time‑tracking module, fixed in versions 16.6.7 and 17.0.3.
