wekan
Enterprise Softwareoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting wekan.
- CVE-2026-68901WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of Service6.5
- CVE-2026-68900Wekan: Stored XSS in HTML board exports through a card-title second parse7.6
- CVE-2026-68899Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback8.7
- CVE-2026-68561Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule8.8
- CVE-2026-68558Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)8.5
- CVE-2026-68559Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`)6.5
- CVE-2026-55652Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)9.8
- CVE-2026-55234Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)8.5
- CVE-2026-53447Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID6.5
- CVE-2026-52892Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops)6.5
- CVE-2026-52891Wekan: Shell Injection via Avatar Upload9.9
- CVE-2026-52890Wekan: Arbitrary file read and server DoS via attachment versions.original.path7.1
- CVE-2026-59154Wekan: Checklist direct DDP updates can write checklist data into private boards4.3
- CVE-2026-41455WeKan < 8.35 SSRF via Webhook URL8.5
- CVE-2026-41454WeKan < 8.35 Missing Authorization via Integration REST API8.3