vciy

CVEs we hold for Wekan

Records whose assigning authority named Wekan as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-68901WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote…wekan
CVE-2026-68900Wekan: Stored XSS in HTML board exports through a card-title second parsewekan
CVE-2026-68899Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallbackwekan
CVE-2026-68561Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort`…wekan
CVE-2026-68560Wekan:hell Injection in External Antivirus Scanner Path via asyncExecwekan
CVE-2026-68559Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`)wekan
CVE-2026-68558Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)wekan
CVE-2026-59154Wekan: Checklist direct DDP updates can write checklist data into private boardswekan
CVE-2026-55652Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account…wekan
CVE-2026-55234Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are…wekan
CVE-2026-53447Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by IDwekan
CVE-2026-53446Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLswekan
CVE-2026-53445Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boardswekan
CVE-2026-53444Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to adminwekan
CVE-2026-52893Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hookwekan
CVE-2026-52892Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on…wekan
CVE-2026-52891Wekan: Shell Injection via Avatar Uploadwekan
CVE-2026-52890Wekan: Arbitrary file read and server DoS via attachment versions.original.pathwekan
CVE-2026-41455WeKan < 8.35 SSRF via Webhook URLwekan
CVE-2026-41454WeKan < 8.35 Missing Authorization via Integration REST APIwekan
CVE-2026-30847Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session TokensWekan
CVE-2026-30846Wekan Exposes All Global Webhook Integrations through globalwebhooks PublicationWekan
CVE-2026-30845Wekan Exposes Sensitive Data through Lack of Field Filtering During Board PublicationWekan
CVE-2026-30844Wekan Vulnerable to SSRF through Lack of Validation or Filtering in Attachment URL LoadingWekan
CVE-2026-30843Wekan has Cross-Board IDOR in Custom Fields Update EndpointsWekan
CVE-2026-25859WeKan < 8.20 Migration Functionality Insufficient Permission ChecksWeKan
CVE-2026-25568WeKan < 8.19 allowPrivateOnly Setting Enforcement BypassWeKan
CVE-2026-25567WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorIdWeKan
CVE-2026-25566WeKan < 8.19 Cross-board Card Move Without Destination AuthorizationWeKan
CVE-2026-25565WeKan < 8.19 Read-only Board Roles Can Update CardsWeKan
CVE-2026-25564WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship ValidationWeKan
CVE-2026-25563WeKan < 8.19 Checklist Creation Cross-Board IDORWeKan
CVE-2026-25562WeKan < 8.19 Attachments Publication Information DisclosureWeKan
CVE-2026-25561WeKan < 8.19 Attachment Upload Object Relationship Validation BypassWeKan
CVE-2026-25560WeKan < 8.19 LDAP Authentication Filter InjectionWeKan
CVE-2026-2209WeKan Custom Translation translationBody.js setCreateTranslation improper authorizationn/a WeKan
CVE-2026-2208WeKan Rules rules.js RulesBleed authorizationn/a WeKan
CVE-2026-2207WeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosuren/a WeKan
CVE-2026-2206WeKan Administrative Repair fixDuplicateLists.js FixDuplicateBleed access controln/a WeKan
CVE-2026-2205WeKan Meteor Publication cards.js CardPubSubBleed information disclosuren/a WeKan
CVE-2026-1964WeKan REST Endpoint boards.js BoardTitleRESTBleed access controln/a WeKan
CVE-2026-1963WeKan Attachment Storage attachments.js MoveStorageBleed access controln/a WeKan
CVE-2026-1962WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access controln/a WeKan
CVE-2026-1898WeKan LDAP User Sync syncUser.js SyncLDAPBleed access controln/a WeKan
CVE-2026-1897WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorizationn/a WeKan
CVE-2026-1896WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration MigrationBleed access controln/a WeKan
CVE-2026-1895WeKan Attachment Storage lists.js applyWipLimit ListWIPBleed access controln/a WeKan
CVE-2026-1894WeKan REST API checklistItems.js Checklist REST Bleed improper authorizationn/a WeKan
CVE-2026-1892WeKan REST API boards.js setBoardOrgs improper authorizationn/a WeKan
CVE-2021-20654no title heldWekan

50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.