CVEs we hold for Kanboard
Records whose assigning authority named Kanboard as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-56774Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session IDkanboard
CVE-2026-29056Kanboard's privilege escalation via mass assignment in user invite registration allows any invited user to become adminkanboard
CVE-2026-25924Kanboard is Missing Access Control on Plugin Installation leading to Administrative RCEkanboard
CVE-2026-25531Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projectskanboard
CVE-2026-25530Kanboard is missing authorization check in getSwimlane API allows cross-project data accesskanboard
CVE-2026-24885Kanboard Affected by Cross-Site Request Forgery (CSRF) via Content-Type Misconfiguration in Project Role Assignmentkanboard
CVE-2026-21880Kanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information Disclosurekanboard
CVE-2025-55010Kanboard Authenticated Admin Remote Code Execution via Unsafe Deserialization of Eventskanboard
CVE-2025-52576Kanboard vulnerable to Username Enumeration via Login Behavior and Bruteforce Protection Bypasskanboard
CVE-2024-54001Kanboard allows a persistent HTML injection site scripting in settings page date formatkanboard
CVE-2023-33969Stored Cross site scripting in the Task External Link Functionality in Kanboardkanboard
CVE-2023-33956Parameter based Indirect Object Referencing leading to private file exposure in Kanboardkanboard
28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.