CVE-2026-57862
- EPSS 0.29%
- Veröffentlicht 30.07.2026 15:26:23
- Zuletzt bearbeitet 31.07.2026 12:16:52
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded i...
CVE-2026-58660
- EPSS 0.36%
- Veröffentlicht 15.07.2026 17:03:17
- Zuletzt bearbeitet 15.07.2026 21:02:41
Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actuall...
CVE-2026-56774
- EPSS 0.27%
- Veröffentlicht 25.06.2026 18:10:22
- Zuletzt bearbeitet 14.07.2026 22:17:21
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessio...
CVE-2026-33058
- EPSS 0.28%
- Veröffentlicht 18.03.2026 02:17:03
- Zuletzt bearbeitet 18.03.2026 17:52:14
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the ent...
CVE-2026-29056
- EPSS 0.37%
- Veröffentlicht 18.03.2026 02:16:24
- Zuletzt bearbeitet 18.03.2026 19:40:48
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without fil...
CVE-2026-25531
- EPSS 0.22%
- Veröffentlicht 13.02.2026 15:15:57
- Zuletzt bearbeitet 13.02.2026 20:43:30
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowin...
CVE-2026-25924
- EPSS 0.49%
- Veröffentlicht 11.02.2026 20:43:19
- Zuletzt bearbeitet 13.02.2026 21:30:01
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application co...
CVE-2026-25530
- EPSS 0.24%
- Veröffentlicht 10.02.2026 16:47:58
- Zuletzt bearbeitet 13.02.2026 20:21:29
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerab...
- EPSS 0.18%
- Veröffentlicht 10.02.2026 16:40:01
- Zuletzt bearbeitet 13.02.2026 20:19:00
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enf...
CVE-2026-21881
- EPSS 0.44%
- Veröffentlicht 08.01.2026 01:08:01
- Zuletzt bearbeitet 20.01.2026 15:57:22
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication...