CVE-2026-56774
- EPSS 0.27%
- Veröffentlicht 25.06.2026 18:10:22
- Zuletzt bearbeitet 25.06.2026 22:17:02
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessio...
CVE-2026-33058
- EPSS 0.28%
- Veröffentlicht 18.03.2026 02:17:03
- Zuletzt bearbeitet 18.03.2026 17:52:14
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the ent...
CVE-2026-29056
- EPSS 0.37%
- Veröffentlicht 18.03.2026 02:16:24
- Zuletzt bearbeitet 18.03.2026 19:40:48
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without fil...
CVE-2026-25531
- EPSS 0.22%
- Veröffentlicht 13.02.2026 15:15:57
- Zuletzt bearbeitet 13.02.2026 20:43:30
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowin...
CVE-2026-25924
- EPSS 0.49%
- Veröffentlicht 11.02.2026 20:43:19
- Zuletzt bearbeitet 13.02.2026 21:30:01
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application co...
CVE-2026-25530
- EPSS 0.24%
- Veröffentlicht 10.02.2026 16:47:58
- Zuletzt bearbeitet 13.02.2026 20:21:29
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerab...
- EPSS 0.18%
- Veröffentlicht 10.02.2026 16:40:01
- Zuletzt bearbeitet 13.02.2026 20:19:00
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enf...
CVE-2026-21881
- EPSS 0.43%
- Veröffentlicht 08.01.2026 01:08:01
- Zuletzt bearbeitet 20.01.2026 15:57:22
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication...
CVE-2026-21880
- EPSS 0.35%
- Veröffentlicht 08.01.2026 00:59:20
- Zuletzt bearbeitet 20.01.2026 18:38:16
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without p...
CVE-2026-21879
- EPSS 0.26%
- Veröffentlicht 08.01.2026 00:51:50
- Zuletzt bearbeitet 20.01.2026 18:15:10
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs ...