Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wekan HIGH 8.2
CVE-2026-30845

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integr…

Fix: 8.33+
Fix from $1,950 2026-03-06
Wekan HIGH 8.1
CVE-2026-30844

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL…

Patch available
Fix from $1,950 2026-03-06
Wekan HIGH 7.5
CVE-2026-30846

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int…

Fix: 8.33+
Fix from $1,950 2026-03-06
Wekan MEDIUM 6.5
CVE-2026-30847

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user doc…

Fix: 8.33+
Fix from $1,600 2026-03-06
Wekan MEDIUM 6.5
CVE-2026-30843

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which cou…

Patch available
Fix from $1,600 2026-03-06
Wekan HIGH 8.8
CVE-2026-2206

A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of t…

Fix: 8.21+
Fix from $1,950 2026-02-08
Wekan MEDIUM 6.5
CVE-2026-2208

A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the compo…

Fix: 8.21+
Fix from $1,600 2026-02-08
Wekan MEDIUM 5.3
CVE-2026-2207

A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the c…

Fix: 8.21+
Fix from $1,600 2026-02-08
Wekan HIGH 8.8
CVE-2026-25859

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resu…

Fix: 8.20+
Fix from $1,950 2026-02-07
Wekan MEDIUM 6.5
CVE-2026-25565

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than r…

Fix: 8.19+
Fix from $1,600 2026-02-07
Wekan MEDIUM 5.4
CVE-2026-25566

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without …

Fix: 8.19+
Fix from $1,600 2026-02-07
Wekan CRITICAL 9.8
CVE-2026-25560

WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into…

Fix: 8.19+
Fix from $2,300 2026-02-07
Wekan HIGH 7.5
CVE-2026-25561

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifier…

Fix: 8.19+
Fix from $1,950 2026-02-07
Wekan HIGH 7.5
CVE-2026-25563

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio…

Fix: 8.19+
Fix from $1,950 2026-02-07
Wekan HIGH 7.5
CVE-2026-25564

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio…

Fix: 8.19+
Fix from $1,950 2026-02-07
Wekan MEDIUM 5.3
CVE-2026-1964

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. Thi…

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan CRITICAL 9.8
CVE-2026-1963

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage…

Fix: 8.21+
Fix from $2,300 2026-02-05
Wekan CRITICAL 9.8
CVE-2026-1962

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp…

Fix: 8.21+
Fix from $2,300 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1898

A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component …

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1896

A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/mig…

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1895

A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Han…

Fix: 8.21+
Fix from $1,600 2026-02-04
Wekan MEDIUM 5.4
CVE-2026-1894

A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Pe…

Fix: 8.21+
Fix from $1,600 2026-02-04
Wekan MEDIUM 5.0
CVE-2026-1892

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component …

Fix: 8.21+
Fix from $1,600 2026-02-04
Wekan HIGH 8.8
CVE-2025-65780

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire…

Fix: 8.16+
Fix from $1,950 2025-12-15
Wekan HIGH 8.2
CVE-2025-65781

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorizat…

Fix: 8.16+
Fix from $1,950 2025-12-15
Wekan HIGH 8.1
CVE-2025-65778

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with att…

Fix: 8.16+
Fix from $1,950 2025-12-15
Wekan HIGH 7.5
CVE-2025-65779

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a boar…

Fix: 8.16+
Fix from $1,950 2025-12-15
Wekan MEDIUM 6.5
CVE-2025-65782

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling …

Fix: after 8.15
Fix from $1,600 2025-12-15
Wekan MEDIUM 5.4
CVE-2023-28485

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary w…

Fix: 6.75+
Fix from $1,600 2023-06-26
Wekan MEDIUM 5.4
CVE-2023-31779

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in…

Fix: after 6.84
Fix from $1,600 2023-05-22