Frédéric Guillot
25 exploits
Active since Feb 2019
Kanboard < 1.2.29 - Cross-Site Scripting via Malicious Clipboard Content
CVSS 4.4
Kanboard 1.2.26-1.2.44 - Stored Cross-Site Scripting via Project Creation Name Parameter
CVSS 5.4
Kanboard < 1.2.46 - Username Enumeration and Brute-Force Protection Bypass via HTTP Header Spoofing
CVSS 5.3
kanboard < 1.2.50 - Authenticated Remote Code Execution via Plugin Installer Bypass
CVSS 8.4
Kanboard < 1.2.8 - Cross-Site Scripting in Pagination Sorting
CVSS 6.1
Miniflux 2.0.25-2.0.43 - Stored Cross-Site Scripting via Image Proxy Error Handling
CVSS 4.8
Kanboard < 1.2.29 - Cross-Site Scripting via Malicious Clipboard Content
CVSS 4.4
Kanboard < 1.2.30 - Insecure Direct Object Reference via file_id Parameter
CVSS 4.3
Kanboard <1.2.30 - Privilege Escalation
CVSS 5.4
Kanboard < 1.2.30 - Stored Cross-Site Scripting
CVSS 6.4
Kanboard < 1.2.30 - Authenticated Information Disclosure via Task and Project Title Leak
CVSS 5.4
kanboard < 1.2.31 - Authenticated SQL Injection via PicoDB Library
CVSS 7.1
kanboard < 1.2.37 - Improper Access Control in ProjectPermissionController
CVSS 8.2
Kanboard < 1.2.43 - Insufficient Session Expiration in SessionHandler
CVSS 6.5
Miniflux v2 < 2.2.7 - Cross-Site Scripting via Media Proxy CSP Bypass
Kanboard < 1.2.46 - Unauthenticated Password Reset Token Leak via Host Header
CVSS 8.1
Kanboard <1.2.47 - Remote Code Execution
CVSS 9.1
kanboard < 1.2.47 - Unauthenticated Path Traversal and Arbitrary File Write via TaskFile API
CVSS 6.4
Miniflux < 2.2.15 - Open Redirect via Protocol-Relative URL
CVSS 6.1
kanboard < 1.2.49 - Open Redirect via URL Validation Bypass
CVSS 4.7
kanboard < 1.2.49 - LDAP Injection in Authentication Mechanism
CVSS 5.3
Kanboard < 1.2.49 - Unauthenticated Authentication Bypass via Spoofed HTTP Header
CVSS 9.1
kanboard < 1.2.50 - Cross-Site Request Forgery via ProjectPermissionController
CVSS 5.7
Kanboard < 1.2.50 - Authenticated Authorization Bypass via getSwimlane API
CVSS 4.3
kanboard < 1.2.50 - Authenticated Missing Authorization in Task Duplication Endpoint
CVSS 4.3