VYPR

Vendor CVEs

Wekan

All CVEs

52 total · sorted by risk
  • CVE-2023-31779MedMay 22, 2023
    risk 0.00cvss 5.4epss 0.01

    Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

  • CVE-2021-3309HigJan 26, 2021
    risk 0.00cvss 8.1epss 0.02

    packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,

Page 2 of 2