Known Vulnerabilities for products from Wekan Project
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Wekan Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-25859 json | Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission ... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25568 json | WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPriva... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25567 json | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoin... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25566 json | WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination boar... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25565 json | WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board r... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25564 json | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist r... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25563 json | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist r... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25562 json | WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metad... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25561 json | WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate ... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2026-25560 json | WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username in... | Not Provided | 2026-02-07 | 2026-07-14 |
| CVE-2023-31779 json | Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can inse... | 5.4 - MEDIUM | 2023-05-22 | 2023-05-31 |
| CVE-2023-28485 json | A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated use... | 5.4 - MEDIUM | 2023-06-26 | 2023-07-03 |
| CVE-2021-20654 json | Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting.... | 5.4 - MEDIUM | 2021-02-10 | 2021-02-16 |
| CVE-2021-3309 json | packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Ce... | 8.1 - HIGH | 2021-01-26 | 2021-02-02 |
| CVE-2018-1000549 json | Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages tha... | 5.3 - MEDIUM | 2018-06-26 | 2020-08-03 |
Known software with vulnerabilities from Wekan Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Wekan Project | Wekan | 0.10.0 |