Vulnerabilities
Summary — last 7 days
New vulnerabilities2,714▼ 164 vs. last week
Critical / high1,235▼ 317 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)257▲ 221 vs. last week
10 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.42% | — | Kanbanwp Kanban Boards FOR WordpressAI | 11/1/2024 | 6/17/2026 | Missing Authorization vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Deferred | Medium (6.1) | 0.25% | — | Virtosoftware Virto Kanban Board WEB PartAI | 6/25/2024 | 6/17/2026 | An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS. | |
| Deferred | High (7.1) | 0.35% | — | Kanbanwp Kanban BoardsAI | 3/31/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Analyzed | Medium (5.3) | 0.58% | — | Remyandrade Todo List IN Kanban Board | 3/27/2024 | 6/17/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Todo List in Kanban Board 1.0. Affected by this issue is some unknown functionality of the component Add ToDo. The manipulation of the argument Todo leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Analyzed | Critical (9.8) | 0.82% | — | Remyandrade Todo List IN Kanban Board | 3/27/2024 | 6/17/2026 | A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-todo.php. The manipulation of the argument list leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modified | High (7.2) | 0.82% | — | Kanbanwp Kanban Boards FOR Wordpress | 12/29/2023 | 6/17/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Modified | Medium (4.8) | 0.55% | — | Kanbanwp Kanban Boards FOR Wordpress | 6/27/2023 | 6/17/2026 | The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modified | Medium (4.8) | 0.37% | — | Kanbanwp Kanban Boards | 6/22/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | |
| Modified | Medium (4.8) | 0.37% | — | Kanbanwp Kanban Boards FOR Wordpress | 5/9/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | |
| Modified | Medium (5.4) | 0.55% | — | Artezio Kanban Board | 3/16/2018 | 6/17/2026 | The Artezio Kanban Board plugin 1.4 revision 1914 for Atlassian Jira has XSS via the Board Name in a Create New Board action, related to an artezioboard/mainPage.jspa?kanbanId=7#/kanban-view URI. |