Wekan Project

Wekan

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:57:51
  • Zuletzt bearbeitet 10.02.2026 21:58:59

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID t...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:57:32
  • Zuletzt bearbeitet 10.02.2026 21:59:34

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID t...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:57:12
  • Zuletzt bearbeitet 10.02.2026 22:01:03

WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially expos...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:56:52
  • Zuletzt bearbeitet 10.02.2026 22:02:06

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board...

  • EPSS 0.04%
  • Veröffentlicht 07.02.2026 21:56:19
  • Zuletzt bearbeitet 10.02.2026 22:03:03

WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipul...

  • EPSS 0.05%
  • Veröffentlicht 05.02.2026 21:32:07
  • Zuletzt bearbeitet 12.02.2026 17:29:49

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrad...

  • EPSS 0.02%
  • Veröffentlicht 05.02.2026 20:32:08
  • Zuletzt bearbeitet 12.02.2026 17:29:38

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be ini...

  • EPSS 0.02%
  • Veröffentlicht 05.02.2026 00:32:09
  • Zuletzt bearbeitet 10.02.2026 21:46:48

A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It is possible to initiate the att...

  • EPSS 0.01%
  • Veröffentlicht 05.02.2026 00:02:07
  • Zuletzt bearbeitet 10.02.2026 17:47:03

A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attac...

  • EPSS 0.05%
  • Veröffentlicht 04.02.2026 23:32:08
  • Zuletzt bearbeitet 10.02.2026 17:45:59

A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation...