📦 Kanboard

by Kanboard

🔍 What is Kanboard?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21881

CRITICAL CVSS 9.1 Jan 8, 2026

This critical authentication bypass vulnerability in Kanboard allows attackers to impersonate any user, including administrators, by sending spoofed HTTP headers when REVERSE_PROXY_AUTH is enabled. Th...

CVE-2025-55010

CRITICAL CVSS 9.1 Aug 12, 2025

CVE-2025-55010 is an unsafe deserialization vulnerability in Kanboard that allows admin users to execute arbitrary PHP code by manipulating event data. This can lead to remote code execution via web s...

CVE-2024-51747

CRITICAL CVSS 9.1 Nov 11, 2024

This vulnerability allows authenticated Kanboard administrators to read and delete arbitrary files on the server by uploading a modified SQLite database file containing path traversal payloads. The at...

CVE-2025-52560

HIGH CVSS 8.1 Jun 24, 2025

Kanboard versions before 1.2.46 have a password reset vulnerability where attackers can craft malicious reset links that leak tokens to attacker-controlled domains. This occurs when the application_ur...

CVE-2023-36813

HIGH CVSS 7.1 Jul 5, 2023

This SQL injection vulnerability in Kanboard allows authenticated users to execute arbitrary SQL queries, potentially leading to privilege escalation or unauthorized data access. All Kanboard instance...

CVE-2026-25531

MEDIUM CVSS 4.3 Feb 13, 2026

This vulnerability allows authenticated Kanboard users to duplicate tasks into projects they shouldn't have access to, bypassing permission controls. It affects Kanboard installations before version 1...

CVE-2026-25530

MEDIUM CVSS 4.3 Feb 10, 2026

This vulnerability allows authenticated Kanboard users to access swimlane data from projects they shouldn't have permission to view. It affects all Kanboard instances running versions before 1.2.50. T...

CVE-2026-21879

MEDIUM CVSS 4.7 Jan 8, 2026

This CVE describes an Open Redirect vulnerability in Kanboard versions 1.2.48 and below that allows attackers to redirect authenticated users to malicious websites. By crafting URLs like //evil.com, a...

CVE-2026-21880

MEDIUM CVSS 5.3 Jan 8, 2026

Kanboard versions 1.2.48 and below contain an LDAP injection vulnerability in the authentication mechanism. Attackers can manipulate LDAP search filters to enumerate all LDAP users, discover sensitive...

CVE-2025-52576

MEDIUM CVSS 5.3 Jun 25, 2025

This vulnerability in Kanboard allows attackers to enumerate valid usernames and bypass IP-based brute-force protection mechanisms. By analyzing login behavior and manipulating HTTP headers, attackers...

CVE-2025-46825

MEDIUM CVSS 5.4 May 12, 2025

Kanboard versions 1.2.26 through 1.2.44 have a stored cross-site scripting vulnerability in the project creation form's name parameter. Attackers can inject malicious scripts that execute when other u...

CVE-2024-55603

MEDIUM CVSS 6.5 Dec 19, 2024

This vulnerability allows attackers to use expired session IDs to maintain unauthorized access to Kanboard instances. It affects all Kanboard users running versions before 1.2.43 due to improper sessi...