Debian Kanboard vulnerabilities
26 known vulnerabilities affecting debian/kanboard.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH6MEDIUM15LOW1
Vulnerabilities
Page 2 of 2
CVE-2023-32685P4MEDIUMCVSS 4.4fixed in kanboard 1.2.26+ds-3 (forky)2023
CVE-2023-32685 [MEDIUM] CVE-2023-32685: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasti
debian
CVE-2024-54001P4MEDIUMCVSS 5.5fixed in kanboard 1.2.44+ds-1 (forky)2024
CVE-2024-54001 [MEDIUM] CVE-2024-54001: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The vulnerability can become xss if the user input is javascri
debian
CVE-2025-46825P4LOWCVSS 1.3fixed in kanboard 1.2.47+ds-1 (forky)2025
CVE-2025-46825 [LOW] CVE-2025-46825: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross-Site Scripting (XSS) Vulnerability in the `name` parameter of the `http://localhost/?controller=ProjectCreationController&action=create` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other
debian
CVE-2026-25531P4MEDIUMCVSS 5.4fixed in kanboard 1.2.50+ds-1 (forky)2026
CVE-2026-25531 [MEDIUM] CVE-2026-25531: kanboard - Kanboard is project management software focused on Kanban methodology. Prior to ...
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowing authenticated users to duplicate tasks into projects they cannot access. This vulnerability is fixed in 1.2.50.
S
debian
CVE-2026-25530P4MEDIUMCVSS 4.3fixed in kanboard 1.2.50+ds-1 (forky)2026
CVE-2026-25530 [MEDIUM] CVE-2026-25530: kanboard - Kanboard is project management software focused on Kanban methodology. Prior to ...
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerability is fixed in 1.2.50.
Scope: local
forky: resolved (fixed in 1.2.50+ds-1)
sid: resolved (fixed in 1.2.50+ds-1)
debian
CVE-2024-22720P4MEDIUMCVSS 4.8fixed in kanboard 1.2.44+ds-1 (forky)2024
CVE-2024-22720 [MEDIUM] CVE-2024-22720: kanboard - Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
Scope: local
forky: resolved (fixed in 1.2.44+ds-1)
sid: resolved (fixed in 1.2.44+ds-1)
debian
← Previous2 / 2