CVE-2026-33058

MEDIUM

Kanboard has Authenticated SQL Injection in Project Permissions Handler

Title source: cna
STIX 2.1

Description

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the entirety of the kanboard database. Version 1.2.51 fixes the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 19.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
kanboard/kanboard < 1.2.51 (2 CPE variants)
Published Mar 18, 2026
Tracked Since Mar 18, 2026