Stored Cross-Site Scripting Vulnerability in Kanboard Project Management Software
CVE-2025-46825
What is CVE-2025-46825?
The Kanboard project management software has a vulnerability that allows attackers to perform Stored Cross-Site Scripting (XSS) through manipulation of the 'name' parameter in the Project Creation form. This vulnerability affects Kanboard versions 1.2.26 through 1.2.44, where improperly configured content security policies can expose users to malicious scripts embedded in web pages. While a default content security policy may mitigate this risk, misconfigurations can lead to exploitation. Users are advised to upgrade to Kanboard version 1.2.45 or later, which includes a fix for this vulnerability to enhance security against potential script injections.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kanboard >= 1.2.26, < 1.2.45
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
