Kanboard

Kanboard

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 25.06.2026 18:10:22
  • Zuletzt bearbeitet 25.06.2026 22:17:02

Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessio...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 18.03.2026 02:17:03
  • Zuletzt bearbeitet 18.03.2026 17:52:14

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the ent...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 18.03.2026 02:16:24
  • Zuletzt bearbeitet 18.03.2026 19:40:48

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without fil...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 13.02.2026 15:15:57
  • Zuletzt bearbeitet 13.02.2026 20:43:30

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowin...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 11.02.2026 20:43:19
  • Zuletzt bearbeitet 13.02.2026 21:30:01

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application co...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 10.02.2026 16:47:58
  • Zuletzt bearbeitet 13.02.2026 20:21:29

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerab...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 10.02.2026 16:40:01
  • Zuletzt bearbeitet 13.02.2026 20:19:00

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enf...

Medienbericht Exploit
  • EPSS 0.43%
  • Veröffentlicht 08.01.2026 01:08:01
  • Zuletzt bearbeitet 20.01.2026 15:57:22

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication...

Medienbericht Exploit
  • EPSS 0.35%
  • Veröffentlicht 08.01.2026 00:59:20
  • Zuletzt bearbeitet 20.01.2026 18:38:16

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without p...

Medienbericht Exploit
  • EPSS 0.26%
  • Veröffentlicht 08.01.2026 00:51:50
  • Zuletzt bearbeitet 20.01.2026 18:15:10

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs ...