Kanbanwp develops WordPress-based kanban board plugins for task management and workflow visualization, with vulnerabilities centering on web-application input-handling issues including cross-site scripting and code injection. These weakness classes reflect the challenges of sanitizing and validating user-supplied content in plugin environments where execution context boundaries are readily crossed; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kanbanwp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40606HIGH Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a | Dec 29, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-23884MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | May 9, 2023 | 4.8 | 19 | NO | NO |
CVE-2023-0873MEDIUM The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross | Jun 27, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-34368MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | Jun 22, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kanbanwp.
Media articles that mention a CVE ID that affects a product developed by Kanbanwp — matched by CVE ID, not by vendor name.