Extension WordPress

Vulnérabilités FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration

Cette page rassemble les failles publiées pour FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
1Critiques
3Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration

3 fiches

CVE-2026-40784 Moyenne · 4,3
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration

FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration <= 1.91.2 – Authenticated (Board Member+) Insecure Direct Object Reference

The FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.91.2 due to missing validation on a…

Versions affectées

*-1.91.2

Correctif

1.91.3

Publication

15/04/2026

CVE-2026-24561 Moyenne · 4,3
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration

FluentBoards <= 1.91.1 – Missing Authorization

The FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-1.91.1

Correctif

1.91.2

Publication

22/01/2026

CVE-2025-39551 Critique · 9,8
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration

FluentBoards <= 1.47 – Unauthenticated PHP Object Injection

The FluentBoards plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.47 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…

Versions affectées

*-1.47

Correctif

1.48

Publication

17/04/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités