Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kanboard MEDIUM 6.5
CVE-2026-33058

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. At…

Fix: 1.2.51+
Fix from $1,600 2026-03-18
Kanboard HIGH 8.8
CVE-2026-29056

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteCont…

Fix: 1.2.51+
Fix from $1,950 2026-03-18
Kanboard HIGH 8.4
CVE-2026-25924

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an…

Fix: 1.2.50+
Fix from $1,950 2026-02-11
Kanboard HIGH 8.0
CVE-2026-24885

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in t…

Fix: 1.2.50+
Fix from $1,950 2026-02-10
Kanboard CRITICAL 9.1
CVE-2026-21881

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass wh…

Fix: 1.2.49+
Fix from $2,300 2026-01-08
Kanboard MEDIUM 6.1
CVE-2026-21879

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allow…

Fix: 1.2.49+
Fix from $1,600 2026-01-08
Kanboard MEDIUM 5.3
CVE-2026-21880

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP aut…

Fix: 1.2.49+
Fix from $1,600 2026-01-08
Kanboard HIGH 7.2
CVE-2025-55010

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in t…

Fix: 1.2.47+
Fix from $1,950 2025-08-12
Kanboard MEDIUM 5.3
CVE-2025-55011

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does no…

Fix: 1.2.47+
Fix from $1,600 2025-08-12
Kanboard MEDIUM 5.3
CVE-2025-52576

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumerati…

Fix: 1.2.46+
Fix from $1,600 2025-06-25
Kanboard HIGH 8.8
CVE-2025-52560

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be …

Fix: 1.2.46+
Fix from $1,950 2025-06-24
Kanboard MEDIUM 5.4
CVE-2025-46825

Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross-Site Scripting (XS…

Fix: 1.2.45+
Fix from $1,600 2025-05-12
Kanboard MEDIUM 6.5
CVE-2024-55603

Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their life…

Fix: 1.2.43+
Fix from $1,600 2024-12-19
Kanboard MEDIUM 5.5
CVE-2024-54001

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section…

No fix yet
Fix from $1,600 2024-12-05
Kanboard HIGH 7.2
CVE-2024-51747

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files f…

Fix: 1.2.42+
Fix from $1,950 2024-11-11
Kanboard HIGH 7.2
CVE-2024-51748

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the ser…

Fix: 1.2.42+
Fix from $1,950 2024-11-11
Kanboard MEDIUM 6.3
CVE-2024-36399

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio…

Fix: 1.2.37+
Fix from $1,600 2024-06-06
Kanboard HIGH 8.8
CVE-2023-36813

Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQ…

Fix: 1.2.31+
Fix from $1,950 2023-07-05
Kanboard MEDIUM 6.5
CVE-2023-33956

Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direc…

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Kanboard MEDIUM 6.5
CVE-2023-33970

Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing access control` was…

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Kanboard MEDIUM 5.4
CVE-2023-33968

Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access …

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Kanboard MEDIUM 5.4
CVE-2023-33969

Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to…

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Kanboard MEDIUM 5.4
CVE-2023-32685

Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` elem…

Fix: 1.2.29+
Fix from $1,600 2023-05-30
Kanboard MEDIUM 6.1
CVE-2019-7324

app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.

Fix: 1.2.8+
Fix from $1,600 2019-02-04
Kanboard HIGH 8.8
CVE-2017-12850

An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.

Fix: after 1.0.45
Fix from $1,950 2017-08-14
Kanboard HIGH 8.8
CVE-2017-12851

An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.

Fix: after 1.0.45
Fix from $1,950 2017-08-14
Kanboard MEDIUM 6.8
CVE-2014-3920

Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for r…

Fix: after 1.0.6
Fix from $1,600 2014-07-03