VendorsWekan Projectwekanall versions
Vulnerabilities

Wekan Project Wekan

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2026-25560
WeKan < 8.19 LDAP Authentication Filter Injection
Published 2026-02-07 · Analyzed
9.8EPSS 0.009
CVE-2026-1963
WeKan Attachment Storage attachments.js MoveStorageBleed access control
Published 2026-02-05 · Analyzed
9.8EPSS 0.003
CVE-2026-1962
WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access control
Published 2026-02-05 · Analyzed
9.8EPSS 0.003
CVE-2026-30844
Wekan Vulnerable to SSRF through Lack of Validation or Filtering in Attachment URL Loading
Published 2026-03-06 · Analyzed
9.3EPSS 0.004
CVE-2026-30847
Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session Tokens
Published 2026-03-06 · Analyzed
9.3EPSS 0.004
CVE-2026-30843
Wekan has Cross-Board IDOR in Custom Fields Update Endpoints
Published 2026-03-06 · Analyzed
9.3EPSS 0.004
CVE-2026-25859
WeKan < 8.20 Migration Functionality Insufficient Permission Checks
Published 2026-02-07 · Analyzed
8.8EPSS 0.005
CVE-2025-65780
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privilege escalation and unauthorized access to other teams/orgs.
Published 2025-12-15 · Analyzed
8.8EPSS 0.003
CVE-2026-2206
WeKan Administrative Repair fixDuplicateLists.js FixDuplicateBleed access control
Published 2026-02-08 · Analyzed
8.8EPSS 0.002
CVE-2026-30846
Wekan Exposes All Global Webhook Integrations through globalwebhooks Publication
Published 2026-03-06 · Analyzed
8.7EPSS 0.006
CVE-2026-30845
Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication
Published 2026-03-06 · Analyzed
8.2EPSS 0.005
CVE-2025-65781
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.
Published 2025-12-15 · Analyzed
8.2EPSS 0.003
CVE-2021-3309
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,
Published 2021-01-26 · Modified
8.1EPSS 0.017
CVE-2025-65778
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions.
Published 2025-12-15 · Analyzed
8.1EPSS 0.004
CVE-2026-25561
WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass
Published 2026-02-07 · Analyzed
7.5EPSS 0.004
CVE-2026-25563
WeKan < 8.19 Checklist Creation Cross-Board IDOR
Published 2026-02-07 · Analyzed
7.5EPSS 0.004
CVE-2026-25564
WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship Validation
Published 2026-02-07 · Analyzed
7.5EPSS 0.004
CVE-2025-65779
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.
Published 2025-12-15 · Analyzed
7.5EPSS 0.003
CVE-2026-25565
WeKan < 8.19 Read-only Board Roles Can Update Cards
Published 2026-02-07 · Analyzed
7.1EPSS 0.004
CVE-2026-25568
WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass
Published 2026-02-07 · Analyzed
7.1EPSS 0.003
CVE-2026-25566
WeKan < 8.19 Cross-board Card Move Without Destination Authorization
Published 2026-02-07 · Analyzed
7.1EPSS 0.003
CVE-2026-2207
WeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosure
Published 2026-02-08 · Analyzed
6.9EPSS 0.004
CVE-2026-1896
WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration MigrationBleed access control
Published 2026-02-04 · Analyzed
6.5EPSS 0.003
CVE-2026-1895
WeKan Attachment Storage lists.js applyWipLimit ListWIPBleed access control
Published 2026-02-04 · Modified
6.5EPSS 0.003
CVE-2026-1898
WeKan LDAP User Sync syncUser.js SyncLDAPBleed access control
Published 2026-02-05 · Analyzed
6.5EPSS 0.003
CVE-2025-65782
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in vote.positive / vote.negative arrays, enabling vote forgery and unauthorized voting.
Published 2025-12-15 · Analyzed
6.5EPSS 0.003
CVE-2026-2208
WeKan Rules rules.js RulesBleed authorization
Published 2026-02-08 · Analyzed
6.5EPSS 0.003
CVE-2026-1894
WeKan REST API checklistItems.js Checklist REST Bleed improper authorization
Published 2026-02-04 · Analyzed
6.5EPSS 0.003
CVE-2026-2209
WeKan Custom Translation translationBody.js setCreateTranslation improper authorization
Published 2026-02-08 · Analyzed
6.5EPSS 0.002
CVE-2023-28485
A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.
Published 2023-06-26 · Modified
5.4EPSS 0.010
CVE-2021-20654
Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.
Published 2021-02-10 · Modified
5.4EPSS 0.008
CVE-2023-31779
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.
Published 2023-05-22 · Modified
5.4EPSS 0.006
CVE-2018-1000549
Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can result in A remote attacker could perform a brute force attack to obtain valid usernames and email addresses.. This attack appear to be exploitable via HTTP Request.
Published 2018-06-26 · Modified
5.3EPSS 0.013
CVE-2026-25562
WeKan < 8.19 Attachments Publication Information Disclosure
Published 2026-02-07 · Analyzed
5.3EPSS 0.004
CVE-2026-25567
WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId
Published 2026-02-07 · Analyzed
5.3EPSS 0.003
CVE-2026-1897
WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization
Published 2026-02-05 · Analyzed
5.3EPSS 0.003
CVE-2026-2205
WeKan Meteor Publication cards.js CardPubSubBleed information disclosure
Published 2026-02-08 · Analyzed
5.3EPSS 0.002
CVE-2026-1964
WeKan REST Endpoint boards.js BoardTitleRESTBleed access control
Published 2026-02-05 · Analyzed
5.3EPSS 0.002
CVE-2026-1892
WeKan REST API boards.js setBoardOrgs improper authorization
Published 2026-02-04 · Analyzed
5.0EPSS 0.003