VYPR

Wekan

by Wekan

Source repositories

CVEs (59)

  • CVE-2026-25567MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier.

  • CVE-2026-25562MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to…

  • CVE-2026-55652CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker…

  • CVE-2026-55234HigJul 15, 2026
    risk 0.00cvss 8.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update…

  • CVE-2026-53447MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any…

  • CVE-2026-53446MedJul 15, 2026
    risk 0.00cvss —epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by server/notifications/outgoing.js without applying the existing validateAttachmentUrl() private-network checks…

  • CVE-2026-53445HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board ID without checking this.userId, membership, or admin access. Any authenticated user can copy a private…

  • CVE-2026-53444HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/models/team.js are globally callable without the admin authorization checks used by their non-OIDC…

  • CVE-2026-52893CriJul 15, 2026
    risk 0.00cvss —epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, without verifying ownership or checking…

  • CVE-2026-52892MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating custom-field routes. A read-only board…

  • CVE-2026-52891CriJul 15, 2026
    risk 0.00cvss 9.9epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/fileValidation.js used a shell command…

  • CVE-2026-52890HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The…

  • CVE-2026-59154MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists and ChecklistItems because updates are authorized only against the current source doc.cardId and do not inspect…

  • CVE-2026-30847MedMar 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user documents with no field filtering, causing the ReactiveCache.getUsers() call to return all fields including highly sensitive data…

  • CVE-2026-30846HigMar 6, 2026
    risk 0.00cvss 7.5epss 0.00

    Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authentication check on the server side. Although…

  • CVE-2026-30845HigMar 6, 2026
    risk 0.00cvss 8.2epss 0.00

    Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data for a board without any field filtering, exposing sensitive fields including webhook URLs and authentication tokens to…

  • CVE-2026-30844HigMar 6, 2026
    risk 0.00cvss 8.1epss 0.00

    Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. During board import in Wekan, attachment URLs from user-supplied JSON data are fetched directly by the server without…

  • CVE-2026-30843MedMar 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards through its custom fields update endpoints, potentially leading…

  • CVE-2026-2209MedFeb 8, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can…

  • CVE-2026-2208MedFeb 8, 2026
    risk 0.00cvss 4.3epss 0.00

    A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version…