Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2026-25531

Medium priority
Needs evaluation

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for...

2 affected packages

kanboard-cli, python-kanboard

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kanboard-cli Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-kanboard Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25924

Medium priority
Needs evaluation

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution...

2 affected packages

kanboard-cli, python-kanboard

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kanboard-cli Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-kanboard Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25530

Medium priority
Needs evaluation

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot...

2 affected packages

kanboard-cli, python-kanboard

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kanboard-cli Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-kanboard Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24885

Medium priority
Needs evaluation

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application...

2 affected packages

kanboard-cli, python-kanboard

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kanboard-cli Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-kanboard Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-4472

Medium priority
Needs evaluation

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

1 affected package

mistral-dashboard

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mistral-dashboard Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-45956

Medium priority
Ignored

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

1 affected package

boa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
boa Not in release Not in release Not in release
Show less packages

CVE-2022-44117

Medium priority
Ignored

Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

1 affected package

boa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
boa Not in release Not in release Not in release
Show less packages

CVE-2021-33558

Medium priority
Ignored

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report...

1 affected package

boa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
boa Not in release Not in release Not in release
Show less packages

CVE-2018-21028

Medium priority

Not in release

Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.

1 affected package

boa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
boa Not in release
Show less packages

CVE-2018-21027

Medium priority

Not in release

Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.

1 affected package

boa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
boa Not in release
Show less packages