| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| OpenProject 16.6.10 source code.tar.gz | 2026-03-31 | 300.7 MB | |
| OpenProject 16.6.10 source code.zip | 2026-03-31 | 316.2 MB | |
| README.md | 2026-03-31 | 1.2 kB | |
| Totals: 3 Items | 616.8 MB | 0 | |
Release date: 2026-03-31
We released OpenProject OpenProject 16.6.10. The release contains several bug fixes and we recommend updating to the newest version. Below you will find a complete list of all changes and bug fixes.
Security fixes
CVE-2026-34717 - SQL Injection in Cost Reporting =n Operator via parse_number_string
The =n operator in cost reports did not appropriately treat user input
This vulnerability was reported by user Ochk0 through a GitHub security advisory. Thank you for responsibly disclosing your findings.
For more information, please see the GitHub advisory #GHSA-5rrm-6qmq-2364