Wekan Project

Wekan

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 26.06.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:55:12

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within t...

  • EPSS 0.2%
  • Veröffentlicht 22.05.2023 13:15:09
  • Zuletzt bearbeitet 28.01.2025 17:15:14

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 10.02.2021 09:15:12
  • Zuletzt bearbeitet 21.11.2024 05:46:57

Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 26.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:21:15

packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,

  • EPSS 0.29%
  • Veröffentlicht 26.06.2018 16:29:02
  • Zuletzt bearbeitet 21.11.2024 03:40:10

Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can result in A remote attacker could perform a brute force attack to obtain valid usernames and email addresses.. This att...