VYPR

4gaboards

by RARgames

Source repositories

CVEs (6)

  • CVE-2026-50191HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.00

    4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The…

  • CVE-2026-50186HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.01

    4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards/download.js, the decoded…

  • CVE-2026-53958HigAug 18, 2026
    risk 0.42cvss 7.6epss 0.00

    4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through…

  • CVE-2026-41419HigApr 24, 2026
    risk 0.42cvss 7.6epss 0.00

    4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbitrary host files as board attachments during BOARDS archive import. Once…

  • CVE-2026-53959MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The users/index and users/show…

  • CVE-2026-41418MedApr 24, 2026
    risk 0.27cvss 5.3epss 0.00

    4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately…