Wekan Project

Wekan

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 07.02.2026 22:16:02
  • Zuletzt bearbeitet 10.02.2026 21:54:37

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

  • EPSS 0.03%
  • Veröffentlicht 07.02.2026 21:59:13
  • Zuletzt bearbeitet 10.02.2026 21:55:34

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public b...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:58:53
  • Zuletzt bearbeitet 10.02.2026 21:56:33

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:58:33
  • Zuletzt bearbeitet 18.02.2026 20:43:46

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects bel...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:58:13
  • Zuletzt bearbeitet 10.02.2026 21:57:16

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that sho...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:57:51
  • Zuletzt bearbeitet 10.02.2026 21:58:59

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID t...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:57:32
  • Zuletzt bearbeitet 10.02.2026 21:59:34

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID t...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:57:12
  • Zuletzt bearbeitet 10.02.2026 22:01:03

WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially expos...

  • EPSS 0.01%
  • Veröffentlicht 07.02.2026 21:56:52
  • Zuletzt bearbeitet 10.02.2026 22:02:06

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board...

  • EPSS 0.05%
  • Veröffentlicht 07.02.2026 21:56:19
  • Zuletzt bearbeitet 10.02.2026 22:03:03

WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipul...