Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wekan — Vulnerabilities & Security Advisories 28

Browse all 28 CVE security advisories affecting wekan. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WeKan serves as an open-source Kanban board application for team project management. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, contributing to its 17 recorded CVEs. Notable security characteristics include its self-hosted nature, which allows organizations to maintain control over their data but requires diligent patch management. While no major public security incidents have been widely documented, the consistent discovery of vulnerabilities in areas such as authentication and file handling underscores the importance of regular security updates for deployments handling sensitive project information.

Top products by wekan: WeKan
CVE IDTitleCVSSSeverityPublished
CVE-2026-55652 Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin) — wekanCWE-287 9.8 Critical2026-07-15
CVE-2026-55234 Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule) — wekanCWE-284 8.5 High2026-07-15
CVE-2026-53447 Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID — wekanCWE-639 6.5 Medium2026-07-15
CVE-2026-52893 Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook — wekanCWE-287--2026-07-15
CVE-2026-53444 Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin — wekanCWE-269--2026-07-15
CVE-2026-53445 Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boards — wekanCWE-862--2026-07-15
CVE-2026-53446 Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs — wekanCWE-918--2026-07-15
CVE-2026-52892 Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops) — wekanCWE-862 6.5 Medium2026-07-15
CVE-2026-52891 Wekan: Shell Injection via Avatar Upload — wekanCWE-78 9.9 Critical2026-07-15
CVE-2026-52890 Wekan: Arbitrary file read and server DoS via attachment versions.original.path — wekanCWE-22 7.1 High2026-07-15
CVE-2026-59154 Wekan: Checklist direct DDP updates can write checklist data into private boards — wekanCWE-863 4.3 Medium2026-07-10
CVE-2026-41455 WeKan < 8.35 SSRF via Webhook URL — wekanCWE-918 8.5 High2026-04-22
CVE-2026-41454 WeKan < 8.35 Missing Authorization via Integration REST API — wekanCWE-862 8.3 High2026-04-22
CVE-2026-30847 Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session Tokens — WekanCWE-200 6.5 -2026-03-06
CVE-2026-30846 Wekan Exposes All Global Webhook Integrations through globalwebhooks Publication — WekanCWE-306 7.5 -2026-03-06
CVE-2026-30845 Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication — WekanCWE-200 7.5 -2026-03-06
CVE-2026-30844 Wekan Vulnerable to SSRF through Lack of Validation or Filtering in Attachment URL Loading — WekanCWE-918 9.1 -2026-03-06
CVE-2026-30843 Wekan has Cross-Board IDOR in Custom Fields Update Endpoints — WekanCWE-639 6.5 -2026-03-06
CVE-2026-25859 WeKan < 8.20 Migration Functionality Insufficient Permission Checks — WeKanCWE-863 7.1AIHighAI2026-02-07
CVE-2026-25568 WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass — WeKanCWE-863 6.5AIMediumAI2026-02-07
CVE-2026-25567 WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId — WeKanCWE-639 6.5AIMediumAI2026-02-07
CVE-2026-25566 WeKan < 8.19 Cross-board Card Move Without Destination Authorization — WeKanCWE-863 3.3AILowAI2026-02-07
CVE-2026-25565 WeKan < 8.19 Read-only Board Roles Can Update Cards — WeKanCWE-863 4.3AIMediumAI2026-02-07
CVE-2026-25564 WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship Validation — WeKanCWE-639 6.5AIMediumAI2026-02-07
CVE-2026-25563 WeKan < 8.19 Checklist Creation Cross-Board IDOR — WeKanCWE-639 6.5AIMediumAI2026-02-07
CVE-2026-25562 WeKan < 8.19 Attachments Publication Information Disclosure — WeKanCWE-203 5.3AIMediumAI2026-02-07
CVE-2026-25561 WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass — WeKanCWE-863 7.5AIHighAI2026-02-07
CVE-2026-25560 WeKan < 8.19 LDAP Authentication Filter Injection — WeKanCWE-90 7.5AIHighAI2026-02-07

This page lists every published CVE security advisory associated with wekan. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.