VYPR
Vendor

Wekan

Products
1
CVEs
59
Across products
59
Status
Private

Products

1

Recent CVEs

59
View all 59 CVEs →
  • CVE-2026-25560CriFeb 7, 2026
    risk 0.64cvss 9.8epss 0.01

    WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during…

  • CVE-2026-25859HigFeb 7, 2026
    risk 0.57cvss 8.8epss 0.01

    Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

  • CVE-2026-68899HigAug 19, 2026
    risk 0.50cvss 8.7epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavailable and the validation fell back…

  • CVE-2026-68561HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included sort. Because Meteor combines…

  • CVE-2026-25564HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating…

  • CVE-2026-25563HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating…

  • CVE-2026-25561HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling…

  • CVE-2026-68558HigAug 19, 2026
    risk 0.48cvss 8.5epss 0.00

    Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line…

  • CVE-2026-41455HigApr 22, 2026
    risk 0.48cvss 8.5epss 0.00

    WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL scheme field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integrations can set webhook URLs…

  • CVE-2026-41454HigApr 22, 2026
    risk 0.47cvss 8.3epss 0.00

    WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs,…

  • CVE-2026-68560HigAug 19, 2026
    risk 0.43cvss —epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path into the administrator-configured externalCommandLine at its {file} placeholder and executed the result through asyncExec, which is promisify(exec) and…

  • CVE-2026-68900HigAug 19, 2026
    risk 0.42cvss 7.6epss 0.00

    Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the…

  • CVE-2026-25565MedFeb 7, 2026
    risk 0.42cvss 6.5epss 0.00

    WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.

  • CVE-2026-68901MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export, /api/boards/:boardId/export/csv, and /api/boards/:boardId/exportExcel handlers in models/export.js and models/exportExcel.js…

  • CVE-2026-68559MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the asynchronous exporterExcel.canExport(user) authorization guard from models/server/ExporterExcel.js without awaiting it. The…

  • CVE-2026-25566MedFeb 7, 2026
    risk 0.35cvss 5.4epss 0.00

    WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board,…

  • CVE-2023-28485MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they…

  • CVE-2021-20654MedFeb 10, 2021
    risk 0.35cvss 5.4epss 0.01

    Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.

  • CVE-2018-1000549MedJun 26, 2018
    risk 0.35cvss 5.3epss 0.01

    Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can result in A remote attacker could perform a brute force attack to obtain valid usernames and email addresses.. This attack appear to be exploitable…

  • CVE-2026-25568MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete…