← Back

Kanboard

kanboard

Vendor: Kanboard • 48 CVEs

CVEs (48)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kanboard
1Kanboard
May 13, 2026
Oct 11, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.
1Kanboard
1Kanboard
May 13, 2026
Oct 11, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
1Kanboard
1Kanboard
May 13, 2026
Oct 11, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
1Kanboard
1Kanboard
May 13, 2026
Oct 11, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
1Kanboard
1Kanboard
May 13, 2026
Oct 11, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.
1Kanboard
1Kanboard
May 13, 2026
Aug 14, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
1Kanboard
1Kanboard
May 13, 2026
Aug 14, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.
1Kanboard
1Kanboard
May 6, 2026
Jul 3, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the defaul...Show more
Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the default URI.Show less