Wekan Project

Wekan

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 06.03.2026 19:37:19
  • Zuletzt bearbeitet 11.03.2026 14:22:57

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user documents with no field filtering, causing the ReactiveCache.getUsers() call to return all fields includ...

  • EPSS 0.16%
  • Veröffentlicht 06.03.2026 19:35:59
  • Zuletzt bearbeitet 11.03.2026 14:24:30

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authentication check on the...

  • EPSS 0.08%
  • Veröffentlicht 06.03.2026 19:34:28
  • Zuletzt bearbeitet 11.03.2026 14:36:50

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data for a board without any field filtering, exposing sensitive fields including webhook URLs ...

  • EPSS 0.03%
  • Veröffentlicht 06.03.2026 19:33:06
  • Zuletzt bearbeitet 11.03.2026 14:56:52

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. During board import in Wekan, attachment URLs from user-supplied JSON data are fetched dire...

  • EPSS 0.03%
  • Veröffentlicht 06.03.2026 19:30:38
  • Zuletzt bearbeitet 11.03.2026 15:49:35

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards through its custom fields update en...

  • EPSS 0.04%
  • Veröffentlicht 08.02.2026 01:14:34
  • Zuletzt bearbeitet 11.02.2026 18:56:51

A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper au...

  • EPSS 0.04%
  • Veröffentlicht 08.02.2026 01:09:41
  • Zuletzt bearbeitet 11.02.2026 18:58:14

A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remo...

  • EPSS 0.05%
  • Veröffentlicht 08.02.2026 01:09:38
  • Zuletzt bearbeitet 11.02.2026 18:58:37

A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the component Activity Publication Handler. Executing a manipulation can lead to information disclosure. I...

  • EPSS 0.06%
  • Veröffentlicht 08.02.2026 01:09:36
  • Zuletzt bearbeitet 11.02.2026 18:58:46

A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access cont...

  • EPSS 0.04%
  • Veröffentlicht 08.02.2026 01:09:32
  • Zuletzt bearbeitet 11.02.2026 18:58:58

A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure. The attack may be performed from...