Kanboard is a compact, open-source project-management and kanban-board application deployed across small teams and organizations for task tracking and workflow visualization. Despite its narrow product footprint, the application's web-facing nature and role in managing potentially sensitive project data have positioned it among the more prominent targets in the vulnerability landscape. The recurring weakness classes center on access-control and input-handling gaps—notably authorization bypass through user-controlled keys, exposure of sensitive information, cross-site scripting, path traversal, and missing authorization checks—reflecting the challenges of securing lightweight web applications that manage shared data. These patterns suggest that defenders deploying Kanboard should prioritize authentication and privilege-boundary verification, restrict network exposure, and maintain current releases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kanboard over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58660HIGH Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-su | Jul 15, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-21881CRITICAL Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enable | Jan 8, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-29056HIGH Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts al | Mar 18, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-56774MEDIUM Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, | Jun 25, 2026 | 5.4 | 28 | NO | NO |
CVE-2017-12851HIGH An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46. | Aug 14, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-12850HIGH An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46. | Aug 14, 2017 | 8.8 | 28 | NO | NO |
CVE-2026-25924HIGH Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to | Feb 11, 2026 | 8.4 | 27 | NO | NO |
CVE-2026-33058MEDIUM Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to | Mar 18, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-24885HIGH Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController | Feb 10, 2026 | 8.0 | 25 | NO | NO |
CVE-2025-55010HIGH Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter | Aug 12, 2025 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kanboard.
Media articles that mention a CVE ID that affects a product developed by Kanboard — matched by CVE ID, not by vendor name.