CVEs we hold for Wekan
Records whose assigning authority named Wekan as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-68901WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote…wekan
CVE-2026-68899Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallbackwekan
CVE-2026-68561Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort`…wekan
CVE-2026-68559Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`)wekan
CVE-2026-68558Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)wekan
CVE-2026-55652Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account…wekan
CVE-2026-55234Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are…wekan
CVE-2026-53447Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by IDwekan
CVE-2026-53445Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boardswekan
CVE-2026-53444Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to adminwekan
CVE-2026-52893Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hookwekan
CVE-2026-52892Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on…wekan
CVE-2026-30847Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session TokensWekan
CVE-2026-30845Wekan Exposes Sensitive Data through Lack of Field Filtering During Board PublicationWekan
CVE-2026-30844Wekan Vulnerable to SSRF through Lack of Validation or Filtering in Attachment URL LoadingWekan
CVE-2026-2209WeKan Custom Translation translationBody.js setCreateTranslation improper authorizationn/a WeKan
CVE-2026-2207WeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosuren/a WeKan
CVE-2026-2206WeKan Administrative Repair fixDuplicateLists.js FixDuplicateBleed access controln/a WeKan
CVE-2026-1962WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access controln/a WeKan
CVE-2026-1897WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorizationn/a WeKan
CVE-2026-1896WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration MigrationBleed access controln/a WeKan
50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.