CVE-2026-25531
- EPSS 0.03%
- Veröffentlicht 13.02.2026 15:15:57
- Zuletzt bearbeitet 13.02.2026 20:43:30
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowin...
CVE-2026-25924
- EPSS 0.06%
- Veröffentlicht 11.02.2026 20:43:19
- Zuletzt bearbeitet 13.02.2026 21:30:01
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application co...
CVE-2026-25530
- EPSS 0.03%
- Veröffentlicht 10.02.2026 16:47:58
- Zuletzt bearbeitet 13.02.2026 20:21:29
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerab...
- EPSS 0.02%
- Veröffentlicht 10.02.2026 16:40:01
- Zuletzt bearbeitet 13.02.2026 20:19:00
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enf...
CVE-2026-21881
- EPSS 0.31%
- Veröffentlicht 08.01.2026 01:08:01
- Zuletzt bearbeitet 20.01.2026 15:57:22
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication...
CVE-2026-21880
- EPSS 0.16%
- Veröffentlicht 08.01.2026 00:59:20
- Zuletzt bearbeitet 20.01.2026 18:38:16
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without p...
CVE-2026-21879
- EPSS 0.04%
- Veröffentlicht 08.01.2026 00:51:50
- Zuletzt bearbeitet 20.01.2026 18:15:10
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs ...
CVE-2025-55010
- EPSS 2.6%
- Veröffentlicht 12.08.2025 15:57:13
- Zuletzt bearbeitet 22.08.2025 17:28:18
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects b...
CVE-2025-55011
- EPSS 0.06%
- Veröffentlicht 12.08.2025 15:57:08
- Zuletzt bearbeitet 22.08.2025 17:15:47
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does not validate whether the task_id parameter is a valid task id, nor does it check for path traversal. As...
CVE-2025-52576
- EPSS 0.06%
- Veröffentlicht 25.06.2025 16:46:01
- Zuletzt bearbeitet 22.08.2025 18:23:53
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumeration and IP spoofing-based brute-force protection bypass. By analyzing login behavior and abusing trust...