Home/Product/kanboard
Product

kanboard

49 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33058
< 1.2.51
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injectio
6.5MEDIUM
CVE-2026-29056
< 1.2.51
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoi
8.8HIGH
CVE-2026-25531
< 1.2.50
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete.
4.3MEDIUM
CVE-2026-25924
< 1.2.50
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in
8.4HIGH
CVE-2026-25530
< 1.2.50
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-l
4.3MEDIUM
CVE-2026-24885
< 1.2.50
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulner
5.7MEDIUM
CVE-2026-21881
< 1.2.49
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authe
9.1CRITICAL
CVE-2026-21880
< 1.2.49
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerabil
5.3MEDIUM
CVE-2026-21879
< 1.2.49
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirec
4.7MEDIUM
CVE-2025-55011
< 1.2.47
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method
6.4MEDIUM
CVE-2025-55010
< 1.2.47
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization
9.1CRITICAL
CVE-2025-52576
< 1.2.46
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to
5.3MEDIUM
CVE-2025-52560
< 1.2.46
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password
8.1HIGH
CVE-2025-46825
>= 1.2.26 and < 1.2.45
Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross
5.4MEDIUM
CVE-2024-55603
< 1.2.43
Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable eve
6.5MEDIUM
CVE-2024-54001
all versions
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the applicati
5.5MEDIUM
CVE-2024-51748
< 1.2.42
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary
9.1CRITICAL
CVE-2024-51747
< 1.2.42
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delet
9.1CRITICAL
CVE-2024-36399
< 1.2.37
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionCon
8.2HIGH
CVE-2024-22720
all versions
Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
4.8MEDIUM
CVE-2023-36813
< 1.2.31
Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is a
7.1HIGH
CVE-2023-33970
< 1.2.30
Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing
5.4MEDIUM
CVE-2023-33969
< 1.2.30
Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) al
6.4MEDIUM
CVE-2023-33968
< 1.2.30
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject t
5.4MEDIUM
CVE-2023-33956
< 1.2.30
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject t
4.3MEDIUM
CVE-2023-32685
< 1.2.29
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `co
4.4MEDIUM
CVE-2019-1003020
<= 1.5.10
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.ja
4.3MEDIUM
CVE-2019-7324
< 1.2.8
app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.
6.1MEDIUM
CVE-2017-15212
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of
4.3MEDIUM
CVE-2017-15211
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another u
4.3MEDIUM
CVE-2017-15210
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of a
4.3MEDIUM
CVE-2017-15209
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another u
4.3MEDIUM
CVE-2017-15208
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of ano
4.3MEDIUM
CVE-2017-15207
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user.
4.3MEDIUM
CVE-2017-15206
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another u
4.3MEDIUM
CVE-2017-15205
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another
4.3MEDIUM
CVE-2017-15204
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another
4.3MEDIUM
CVE-2017-15203
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another us
4.3MEDIUM
CVE-2017-15202
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user.
4.3MEDIUM
CVE-2017-15201
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user.
4.3MEDIUM
CVE-2017-15200
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.
4.3MEDIUM
CVE-2017-15199
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as
4.3MEDIUM
CVE-2017-15198
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
4.3MEDIUM
CVE-2017-15197
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another use
4.3MEDIUM
CVE-2017-15196
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
4.3MEDIUM
CVE-2017-15195
all versions
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.
4.3MEDIUM
CVE-2017-12851
<= 1.0.45
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
8.8HIGH
CVE-2017-12850
<= 1.0.45
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboa
8.8HIGH
CVE-2014-3920
<= 1.0.6
Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of a
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin