Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kanboard

First CVE: Jul 3, 2014Active for: 12 yearsTotal CVEs: 50
24.9
VTI Score
Low

Kanboard is a compact, open-source project-management and kanban-board application deployed across small teams and organizations for task tracking and workflow visualization. Despite its narrow product footprint, the application's web-facing nature and role in managing potentially sensitive project data have positioned it among the more prominent targets in the vulnerability landscape. The recurring weakness classes center on access-control and input-handling gaps—notably authorization bypass through user-controlled keys, exposure of sensitive information, cross-site scripting, path traversal, and missing authorization checks—reflecting the challenges of securing lightweight web applications that manage shared data. These patterns suggest that defenders deploying Kanboard should prioritize authentication and privilege-boundary verification, restrict network exposure, and maintain current releases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
7.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kanboard over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2014
12 years ago
Most Recent CVE
Jul 15, 2026
11 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-58660HIGH
Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-su
Jul 15, 20268.133NONO
CVE-2026-21881CRITICAL
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enable
Jan 8, 20269.131NONO
CVE-2026-29056HIGH
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts al
Mar 18, 20268.829NONO
CVE-2026-56774MEDIUM
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove,
Jun 25, 20265.428NONO
CVE-2017-12851HIGH
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
Aug 14, 20178.828NONO
CVE-2017-12850HIGH
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.
Aug 14, 20178.828NONO
CVE-2026-25924HIGH
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to
Feb 11, 20268.427NONO
CVE-2026-33058MEDIUM
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to
Mar 18, 20266.526NONO
CVE-2026-24885HIGH
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController
Feb 10, 20268.025NONO
CVE-2025-55010HIGH
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter
Aug 12, 20257.225NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
76%
22%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network49 (98.0%)
Unknown1 (2.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High0 (0.0%)
Unknown1 (2.0%)
User Interaction
None40 (80.0%)
Unknown1 (2.0%)
Required9 (18.0%)
Privileges Required
Low35 (70.0%)
High6 (12.0%)
None8 (16.0%)
Unknown1 (2.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kanboard.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kanboard — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kanboard's Products

View all 3 CNAs →

Top CWEs