0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑32703, outlining a persistent XSS flaw in OpenProject caused by push access and malicious filenames, without providing a PoC, exploit, or patch.
CVE@CVEnewGeneral
The tweet lists the CVE and affected OpenProject versions but lacks further technical or operational details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces a stored XSS vulnerability (CVE-2026-32703) in OpenProject's Repositories module, but provides no PoC, exploit, patch, or active exploitation evidence.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE-2026-32703 affecting OpenProject versions prior to 16.6.9/17.0.6/17.1.3/17.2.1, noting an improper filename-escaping flaw in the Repositories module, but offers no PoC, exploit, patch, or evidence of active exploitation.
CVEFind.com@CveFindComPatch
The message announces a critical XSS vulnerability in OpenProject with details on the affected versions and provides the fixed release versions, confirming a patch availability.