Kanboard Security Vulnerabilities (CVEs)

Track 12 security vulnerabilities affecting Kanboard products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

3 Critical
2 High
7 Medium
🔔 Get Alerts for Kanboard
CVE-2026-25531 4.3

This vulnerability allows authenticated Kanboard users to duplicate tasks into projects they shouldn't have access to, bypassing permission controls. ...

Feb 13, 2026
CVE-2026-25530 4.3

This vulnerability allows authenticated Kanboard users to access swimlane data from projects they shouldn't have permission to view. It affects all Ka...

Feb 10, 2026
CVE-2026-21879 4.7

This CVE describes an Open Redirect vulnerability in Kanboard versions 1.2.48 and below that allows attackers to redirect authenticated users to malic...

Jan 8, 2026
CVE-2026-21880 5.3

Kanboard versions 1.2.48 and below contain an LDAP injection vulnerability in the authentication mechanism. Attackers can manipulate LDAP search filte...

Jan 8, 2026
CVE-2026-21881 9.1

This critical authentication bypass vulnerability in Kanboard allows attackers to impersonate any user, including administrators, by sending spoofed H...

Jan 8, 2026
CVE-2025-55010 9.1

CVE-2025-55010 is an unsafe deserialization vulnerability in Kanboard that allows admin users to execute arbitrary PHP code by manipulating event data...

Aug 12, 2025
CVE-2025-52576 5.3

This vulnerability in Kanboard allows attackers to enumerate valid usernames and bypass IP-based brute-force protection mechanisms. By analyzing login...

Jun 25, 2025
CVE-2025-52560 8.1

Kanboard versions before 1.2.46 have a password reset vulnerability where attackers can craft malicious reset links that leak tokens to attacker-contr...

Jun 24, 2025
CVE-2025-46825 5.4

Kanboard versions 1.2.26 through 1.2.44 have a stored cross-site scripting vulnerability in the project creation form's name parameter. Attackers can ...

May 12, 2025
CVE-2024-55603 6.5

This vulnerability allows attackers to use expired session IDs to maintain unauthorized access to Kanboard instances. It affects all Kanboard users ru...

Dec 19, 2024
CVE-2024-51747 9.1

This vulnerability allows authenticated Kanboard administrators to read and delete arbitrary files on the server by uploading a modified SQLite databa...

Nov 11, 2024
CVE-2023-36813 7.1

This SQL injection vulnerability in Kanboard allows authenticated users to execute arbitrary SQL queries, potentially leading to privilege escalation ...

Jul 5, 2023

Why Monitor Kanboard Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 12+ known vulnerabilities affecting Kanboard products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Kanboard packages in under 60 seconds. No agents required - completely agentless scanning that works across Kanboard deployments.

Free vulnerability database: Access detailed information about every Kanboard CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Kanboard CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Kanboard CVEs Free