Known Vulnerabilities for products from Wekan Project

Listed below are 15 of the newest known vulnerabilities associated with the vendor "Wekan Project".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-25859 json Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission ... Not Provided 2026-02-07 2026-07-14
CVE-2026-25568 json WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPriva... Not Provided 2026-02-07 2026-07-14
CVE-2026-25567 json WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoin... Not Provided 2026-02-07 2026-07-14
CVE-2026-25566 json WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination boar... Not Provided 2026-02-07 2026-07-14
CVE-2026-25565 json WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board r... Not Provided 2026-02-07 2026-07-14
CVE-2026-25564 json WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist r... Not Provided 2026-02-07 2026-07-14
CVE-2026-25563 json WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist r... Not Provided 2026-02-07 2026-07-14
CVE-2026-25562 json WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metad... Not Provided 2026-02-07 2026-07-14
CVE-2026-25561 json WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate ... Not Provided 2026-02-07 2026-07-14
CVE-2026-25560 json WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username in... Not Provided 2026-02-07 2026-07-14
CVE-2023-31779 json Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can inse... 5.4 - MEDIUM 2023-05-22 2023-05-31
CVE-2023-28485 json A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated use... 5.4 - MEDIUM 2023-06-26 2023-07-03
CVE-2021-20654 json Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting.... 5.4 - MEDIUM 2021-02-10 2021-02-16
CVE-2021-3309 json packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Ce... 8.1 - HIGH 2021-01-26 2021-02-02
CVE-2018-1000549 json Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages tha... 5.3 - MEDIUM 2018-06-26 2020-08-03

Known software with vulnerabilities from Wekan Project

Type Vendor Product Version
ApplicationWekan ProjectWekan0.10.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report