In Kanboard versions prior to 1.2.47 a medium severity vulnerability CVE-2025-55011 was detected. This vulnerability allows attackers to write files anywhere on the system the application user controls due to missing validation of the task_id parameter and lack of path traversal checks in the createTaskFile API method. To address this issue users should upgrade Kanboard to version 1.2.47 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-55011.
Read more Project ManagementIn Kanboard versions prior to 1.2.47 a critical severity vulnerability CVE-2025-55010 was detected. This vulnerability allows attackers with admin access to achieve remote code execution by exploiting unsafe deserialization in the ProjectEventActivityFormatter via the event[“data”] field in the project_activities table, potentially writing a web shell to the /plugins folder. To address this issue, users should upgrade Kanboard to version 1.2.47 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-55010.
Read more Project ManagementIn Kimai versions 0.9.2.beta, 0.9.2.1294.beta and 0.9.2.1306-3 a critical severity vulnerability CVE-2013-10033 was detected. This vulnerability allows unauthenticated attackers to perform SQL injection via the db_restore.php endpoint’s dates[] POST parameter, which under certain conditions can be exploited to write arbitrary files and achieve remote code execution. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2013-10033.
Read more Project ManagementIn Kanboard versions 1.2.45 and prior a medium severity vulnerability CVE-2025-52576 was detected. This vulnerability allows attackers to enumerate valid usernames and bypass IP-based brute-force protection mechanisms such as Fail2Ban or CAPTCHA by abusing trusted HTTP headers and analyzing login behavior. This puts user accounts at higher risk of credential stuffing and brute-force attacks. To address this issue, users should upgrade Kanboard to version 1.2.46. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52576.
Read more Project ManagementIn Kanboard versions prior to 1.2.46 a high severity vulnerability CVE-2025-52560 was detected. This vulnerability allows attackers to craft malicious password reset links by exploiting an unvalidated Host header when the application_url configuration is unset, potentially leading to account takeover. To address this issue, users should upgrade Kanboard to versions 1.2.46 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52560.
Read more Project ManagementIn Kanboard versions 1.2.26 through 1.2.44 a low severity vulnerability CVE-2025-46825 was detected. This vulnerability allows attackers to inject malicious scripts via the `name` parameter in the project creation form, potentially executing them in web pages viewed by other users if content security policies are misconfigured. To address this issue, users should upgrade Kanboard to versions 1.2.45. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46825.
Read more Project ManagementIn Redmine versions 6.0.0 through 6.0.3 a medium severity vulnerability CVE-2025-4011 was detected. This vulnerability allows attackers to perform cross-site scripting (XSS) via manipulation of the “Name” argument in the Custom Query Handler. To address this issue, users should upgrade Redmine to versions 6.0.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4011.
Read more Project ManagementIn Kanboard versions 1.2.48 and below a critical severity vulnerability CVE-2026-21881 was detected. This vulnerability allows attackers to bypass authentication and impersonate any user, including administrators, by sending spoofed HTTP headers when REVERSE_PROXY_AUTH is enabled, as the application does not verify that requests originate from a trusted reverse proxy. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21881.
Read more Project ManagementIn Kanboard versions 1.2.48 and below a medium severity vulnerability CVE-2026-21880 was detected. This vulnerability allows attackers to exploit improper input sanitization in the LDAP authentication mechanism to perform LDAP injection, enabling user enumeration and disclosure of sensitive LDAP user attributes. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21880.
Read more Project Management