CVE-2026-23625 | opf openproject up to 16.6.4 link_to_work_package cross site scripting (EUVD-2026-3309)
A vulnerability categorized as problematic has been discovered in opf openproject up to 16.6.4. Affected by this issue is the function link_to_work_package. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-23625. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.