Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-30845 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integr… Wekan 8.33+ Fix from $1,9502026-03-06 HIGH 8.1 CVE-2026-30844 Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL… Wekan Patch available Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-30846 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int… Wekan 8.33+ Fix from $1,9502026-03-06 MEDIUM 6.5 CVE-2026-30847 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user doc… Wekan 8.33+ Fix from $1,6002026-03-06 MEDIUM 6.5 CVE-2026-30843 Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which cou… Wekan Patch available Fix from $1,6002026-03-06 HIGH 8.8 CVE-2026-2206 A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of t… Wekan 8.21+ Fix from $1,9502026-02-08 MEDIUM 6.5 CVE-2026-2208 A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the compo… Wekan 8.21+ Fix from $1,6002026-02-08 MEDIUM 5.3 CVE-2026-2207 A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the c… Wekan 8.21+ Fix from $1,6002026-02-08 HIGH 8.8 CVE-2026-25859 Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resu… Wekan 8.20+ Fix from $1,9502026-02-07 MEDIUM 6.5 CVE-2026-25565 WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than r… Wekan 8.19+ Fix from $1,6002026-02-07 MEDIUM 5.4 CVE-2026-25566 WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without … Wekan 8.19+ Fix from $1,6002026-02-07 CRITICAL 9.8 CVE-2026-25560 WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into… Wekan 8.19+ Fix from $2,3002026-02-07 HIGH 7.5 CVE-2026-25561 WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifier… Wekan 8.19+ Fix from $1,9502026-02-07 HIGH 7.5 CVE-2026-25563 WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio… Wekan 8.19+ Fix from $1,9502026-02-07 HIGH 7.5 CVE-2026-25564 WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio… Wekan 8.19+ Fix from $1,9502026-02-07 MEDIUM 5.3 CVE-2026-1964 A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. Thi… Wekan 8.21+ Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2026-1963 A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage… Wekan 8.21+ Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-1962 A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp… Wekan 8.21+ Fix from $2,3002026-02-05 MEDIUM 6.3 CVE-2026-1898 A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component … Wekan 8.21+ Fix from $1,6002026-02-05 MEDIUM 6.3 CVE-2026-1896 A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/mig… Wekan 8.21+ Fix from $1,6002026-02-05 MEDIUM 6.3 CVE-2026-1895 A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Han… Wekan 8.21+ Fix from $1,6002026-02-04 MEDIUM 5.4 CVE-2026-1894 A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Pe… Wekan 8.21+ Fix from $1,6002026-02-04 MEDIUM 5.0 CVE-2026-1892 A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component … Wekan 8.21+ Fix from $1,6002026-02-04 HIGH 8.8 CVE-2025-65780 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire… Wekan 8.16+ Fix from $1,9502025-12-15 HIGH 8.2 CVE-2025-65781 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorizat… Wekan 8.16+ Fix from $1,9502025-12-15 HIGH 8.1 CVE-2025-65778 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with att… Wekan 8.16+ Fix from $1,9502025-12-15 HIGH 7.5 CVE-2025-65779 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a boar… Wekan 8.16+ Fix from $1,9502025-12-15 MEDIUM 6.5 CVE-2025-65782 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling … Wekan after 8.15 Fix from $1,6002025-12-15 MEDIUM 5.4 CVE-2023-28485 A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary w… Wekan 6.75+ Fix from $1,6002023-06-26 MEDIUM 5.4 CVE-2023-31779 Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in… Wekan after 6.84 Fix from $1,6002023-05-22