Wekan Project

Wekan

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 04.02.2026 23:15:55
  • Zuletzt bearbeitet 23.02.2026 10:16:23

A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remot...

  • EPSS 0.01%
  • Veröffentlicht 04.02.2026 22:32:08
  • Zuletzt bearbeitet 11.02.2026 19:08:27

A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument item.cardId/item.checklistId/card.boardId results in improper...

  • EPSS 0.05%
  • Veröffentlicht 04.02.2026 22:15:58
  • Zuletzt bearbeitet 10.02.2026 17:45:33

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improp...

  • EPSS 0.04%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 23.12.2025 18:08:12

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in ...

  • EPSS 0.06%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 01:35:29

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bear...

  • EPSS 0.06%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 01:37:10

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server...

  • EPSS 0.08%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 01:39:30

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering ...

  • EPSS 0.05%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 01:44:38

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the app...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 26.06.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:55:12

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within t...

  • EPSS 0.22%
  • Veröffentlicht 22.05.2023 13:15:09
  • Zuletzt bearbeitet 28.01.2025 17:15:14

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.