Kanboard

Kanboard

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 30.07.2026 15:26:23
  • Zuletzt bearbeitet 31.07.2026 12:16:52

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded i...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 15.07.2026 17:03:17
  • Zuletzt bearbeitet 15.07.2026 21:02:41

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actuall...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 25.06.2026 18:10:22
  • Zuletzt bearbeitet 14.07.2026 22:17:21

Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessio...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 18.03.2026 02:17:03
  • Zuletzt bearbeitet 18.03.2026 17:52:14

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the ent...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 18.03.2026 02:16:24
  • Zuletzt bearbeitet 18.03.2026 19:40:48

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without fil...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 13.02.2026 15:15:57
  • Zuletzt bearbeitet 13.02.2026 20:43:30

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowin...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 11.02.2026 20:43:19
  • Zuletzt bearbeitet 13.02.2026 21:30:01

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application co...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 10.02.2026 16:47:58
  • Zuletzt bearbeitet 13.02.2026 20:21:29

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerab...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 10.02.2026 16:40:01
  • Zuletzt bearbeitet 13.02.2026 20:19:00

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enf...

Medienbericht Exploit
  • EPSS 0.44%
  • Veröffentlicht 08.01.2026 01:08:01
  • Zuletzt bearbeitet 20.01.2026 15:57:22

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication...