
CVE-2026-52781 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants <macro> elements unrestricted data-* attribut… https://www.cve.org/CVERecord?id=CVE-2026-52781
Post summary
A new vulnerability (CVE‑2026‑52781) affecting OpenProject's HTML sanitizer is disclosed, allowing unrestricted data-* attributes via <macro> elements; no PoC, exploit, or patch details are provided.
