Wekan Project

Wekan

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 08.02.2026 01:14:34
  • Zuletzt bearbeitet 11.02.2026 18:56:51

A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper au...

  • EPSS 0.04%
  • Veröffentlicht 08.02.2026 01:09:41
  • Zuletzt bearbeitet 11.02.2026 18:58:14

A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remo...

  • EPSS 0.05%
  • Veröffentlicht 08.02.2026 01:09:38
  • Zuletzt bearbeitet 11.02.2026 18:58:37

A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the component Activity Publication Handler. Executing a manipulation can lead to information disclosure. I...

  • EPSS 0.05%
  • Veröffentlicht 08.02.2026 01:09:36
  • Zuletzt bearbeitet 11.02.2026 18:58:46

A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access cont...

  • EPSS 0.03%
  • Veröffentlicht 08.02.2026 01:09:32
  • Zuletzt bearbeitet 11.02.2026 18:58:58

A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure. The attack may be performed from...

  • EPSS 0.04%
  • Veröffentlicht 07.02.2026 22:16:02
  • Zuletzt bearbeitet 10.02.2026 21:54:37

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

  • EPSS 0.03%
  • Veröffentlicht 07.02.2026 21:59:13
  • Zuletzt bearbeitet 10.02.2026 21:55:34

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public b...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:58:53
  • Zuletzt bearbeitet 10.02.2026 21:56:33

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:58:33
  • Zuletzt bearbeitet 18.02.2026 20:43:46

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects bel...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:58:13
  • Zuletzt bearbeitet 10.02.2026 21:57:16

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that sho...