vciy

CVEs we hold for Kanboard

Records whose assigning authority named Kanboard as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-58660Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Dropkanboard
CVE-2026-57862Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP NotationKanboard
CVE-2026-56774Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session IDkanboard
CVE-2026-33058Kanboard has Authenticated SQL Injection in Project Permissions Handlerkanboard
CVE-2026-29056Kanboard's privilege escalation via mass assignment in user invite registration allows any invited user to become adminkanboard
CVE-2026-25924Kanboard is Missing Access Control on Plugin Installation leading to Administrative RCEkanboard
CVE-2026-25531Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projectskanboard
CVE-2026-25530Kanboard is missing authorization check in getSwimlane API allows cross-project data accesskanboard
CVE-2026-24885Kanboard Affected by Cross-Site Request Forgery (CSRF) via Content-Type Misconfiguration in Project Role Assignmentkanboard
CVE-2026-21881Kanboard is Vulnerable to Reverse Proxy Authentication Bypasskanboard
CVE-2026-21880Kanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information Disclosurekanboard
CVE-2026-21879Kanboard vulnerable to Open Redirect via protocol-relative URLskanboard
CVE-2025-55011Kanboard Path Traversal in File Write via Task File Upload Apikanboard
CVE-2025-55010Kanboard Authenticated Admin Remote Code Execution via Unsafe Deserialization of Eventskanboard
CVE-2025-52576Kanboard vulnerable to Username Enumeration via Login Behavior and Bruteforce Protection Bypasskanboard
CVE-2025-52560Kanboard Password Reset Poisoning via Host Header Injectionkanboard
CVE-2025-46825Kanboard has stored Cross-site Scripting vulnerability in project namekanboard
CVE-2024-55603Insufficient session invalidation in Kanboardkanboard
CVE-2024-54001Kanboard allows a persistent HTML injection site scripting in settings page date formatkanboard
CVE-2024-51748Remote code execution through language setting in kanboardkanboard
CVE-2024-51747Arbitrary File Read and Delete in kanboardkanboard
CVE-2024-36399Kanboard affected by Project Takeover via IDOR in ProjectPermissionControllerkanboard
CVE-2023-36813Kanboard Authenticated SQL Injections vulnerabilitykanboard
CVE-2023-33970Missing access control in internal task links feature in Kanboardkanboard
CVE-2023-33969Stored Cross site scripting in the Task External Link Functionality in Kanboardkanboard
CVE-2023-33968Missing Access Control allows User to move and duplicate tasks in Kanboardkanboard
CVE-2023-33956Parameter based Indirect Object Referencing leading to private file exposure in Kanboardkanboard
CVE-2023-32685Clipboard based cross-site scripting (blocked with default CSP) in Kanboardkanboard

28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.