[Git][security-tracker-team/security-tracker][master] Track fixed version for kanboard issues fixed via unstable upload

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Feb 17 04:25:26 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8d6ee19b by Salvatore Bonaccorso at 2026-02-17T05:24:50+01:00
Track fixed version for kanboard issues fixed via unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1573,7 +1573,7 @@ CVE-2026-25994 (PJSIP is a free and open source multimedia communication library
 CVE-2026-25935 (Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanc ...)
 	NOT-FOR-US: Vikunja
 CVE-2026-25924 (Kanboard is project management software focused on Kanban methodology. ...)
-	- kanboard <unfixed> (bug #1127924)
+	- kanboard 1.2.50+ds-1 (bug #1127924)
 	NOTE: https://github.com/kanboard/kanboard/security/advisories/GHSA-grch-p7vf-vc4f
 	NOTE: Fixed by: https://github.com/kanboard/kanboard/commit/b9ada89b1a64034612fc4262b88c42458c0d6ee4 (v1.2.50)
 CVE-2026-25759 (Statmatic is a Laravel and Git powered content management system (CMS) ...)
@@ -2358,7 +2358,7 @@ CVE-2025-8099 (GitLab has remediated an issue in GitLab CE/EE affecting all vers
 CVE-2025-7659 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	- gitlab <not-affected> (Vulnerable code not present)
 CVE-2026-25531 (Kanboard is project management software focused on Kanban methodology. ...)
-	- kanboard <unfixed> (bug #1127694)
+	- kanboard 1.2.50+ds-1 (bug #1127694)
 	NOTE: https://github.com/kanboard/kanboard/security/advisories/GHSA-vrm3-3337-whp9
 CVE-2026-2303 (The mongo-go-driver repositorycontains CGo bindings for GSSAPI (Kerber ...)
 	NOT-FOR-US: mongo-go-driver
@@ -2402,11 +2402,11 @@ CVE-2026-25609 (Incorrect validation of the profile command may result in the de
 CVE-2026-25577 (Emmett is a framework designed to simplify your development process. P ...)
 	NOT-FOR-US: Emmett framework
 CVE-2026-25530 (Kanboard is project management software focused on Kanban methodology. ...)
-	- kanboard <unfixed> (bug #1127694)
+	- kanboard 1.2.50+ds-1 (bug #1127694)
 	NOTE: https://github.com/kanboard/kanboard/security/advisories/GHSA-6rxw-vvvj-r93q
 	NOTE: Fixed by: https://github.com/kanboard/kanboard/commit/c3d8d20e05322b09e036fed7afb57194d624a414 (v1.2.50)
 CVE-2026-24885 (Kanboard is project management software focused on Kanban methodology. ...)
-	- kanboard <unfixed> (bug #1127694)
+	- kanboard 1.2.50+ds-1 (bug #1127694)
 	NOTE: https://github.com/kanboard/kanboard/security/advisories/GHSA-582j-h4w4-hwr5
 	NOTE: Fixed by; https://github.com/kanboard/kanboard/commit/2c56d92783d4a3094812c2f7cba50f80a372f95e (v1.2.50)
 CVE-2026-24343 (Improper Neutralization of Data within XPath Expressions ('XPath Injec ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d6ee19b38b47b31e9d362214032c7e30dca2948

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d6ee19b38b47b31e9d362214032c7e30dca2948
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260217/ef08edef/attachment.htm>


More information about the debian-security-tracker-commits mailing list