CVE-2026-25764 | opf openproject up to 16.6.6/17.0.2 time cross site scripting (GHSA-q523-c695-h3hp / EUVD-2026-5557)
A vulnerability categorized as problematic has been discovered in opf openproject up to 16.6.6/17.0.2. Affected by this vulnerability is an unknown functionality of the component time Handler. Such manipulation leads to basic cross site scripting.
This vulnerability is listed as CVE-2026-25764. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.