High severity7.5OSV Advisory· Published Dec 15, 2025· Updated Jun 17, 2026
CVE-2025-65779
CVE-2025-65779
Description
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/wekan/wekan/commit/ea310d7508b344512e5de0dfbc9bdfd38145c5c5nvdPatch
- wekan.fi/hall-of-fame/spacebleed/nvdVendor Advisory
- github.com/wekan/wekan/blob/main/CHANGELOG.mdnvdRelease Notes
News mentions
0No linked articles in our index yet.