Home/Product/wekan project wekan
Product

wekan project wekan

39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-30847
>= 8.31 and < 8.33
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan
6.5MEDIUM
CVE-2026-30846
>= 8.31 and < 8.33
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all
7.5HIGH
CVE-2026-30845
>= 8.31 and < 8.33
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan p
8.2HIGH
CVE-2026-30844
all versions
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF)
8.1HIGH
CVE-2026-30843
all versions
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (ID
6.5MEDIUM
CVE-2026-2209
< 8.19
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/com
6.3MEDIUM
CVE-2026-2208
< 8.21
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/ru
4.3MEDIUM
CVE-2026-2207
< 8.21
A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/act
5.3MEDIUM
CVE-2026-2206
< 8.21
A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDup
6.3MEDIUM
CVE-2026-2205
< 8.21
A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the c
4.3MEDIUM
CVE-2026-25859
< 8.20
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission check
8.8HIGH
CVE-2026-25568
< 8.19
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnl
4.3MEDIUM
CVE-2026-25567
< 8.19
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint acc
4.3MEDIUM
CVE-2026-25566
< 8.19
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/lis
5.4MEDIUM
CVE-2026-25565
< 8.19
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read a
6.5MEDIUM
CVE-2026-25564
< 8.19
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes
7.5HIGH
CVE-2026-25563
< 8.19
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes
7.5HIGH
CVE-2026-25562
< 8.19
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata c
4.3MEDIUM
CVE-2026-25561
< 8.19
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that
7.5HIGH
CVE-2026-25560
< 8.19
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input i
9.8CRITICAL
CVE-2026-1964
< 8.21
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component
4.3MEDIUM
CVE-2026-1963
< 8.21
A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component
6.3MEDIUM
CVE-2026-1962
< 8.21
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigra
6.3MEDIUM
CVE-2026-1898
< 8.21
A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.j
6.3MEDIUM
CVE-2026-1897
< 8.21
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/pos
4.3MEDIUM
CVE-2026-1896
< 8.21
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of
6.3MEDIUM
CVE-2026-1895
< 8.21
A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Att
6.3MEDIUM
CVE-2026-1894
< 8.21
A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the com
6.3MEDIUM
CVE-2026-1892
< 8.21
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.j
5.0MEDIUM
CVE-2025-65782
<= 8.15
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in ca
6.5MEDIUM
CVE-2025-65781
< 8.16
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API tr
8.2HIGH
CVE-2025-65780
< 8.16
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can
8.8HIGH
CVE-2025-65779
< 8.16
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attacker
7.5HIGH
CVE-2025-65778
< 8.16
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can
8.1HIGH
CVE-2023-28485
< 6.75
A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to
5.4MEDIUM
CVE-2023-31779
<= 6.84
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert Ja
5.4MEDIUM
CVE-2021-20654
>= 3.12 and <= 4.11
Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This
5.4MEDIUM
CVE-2021-3309
< 4.87
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certifi
8.1HIGH
CVE-2018-1000549
all versions
Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can
5.3MEDIUM
threatengine.sh