CVE-2026-1964
- EPSS 0.06%
- Veröffentlicht 05.02.2026 21:32:07
- Zuletzt bearbeitet 12.02.2026 17:29:49
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrad...
CVE-2026-1963
- EPSS 0.03%
- Veröffentlicht 05.02.2026 21:02:07
- Zuletzt bearbeitet 06.03.2026 21:50:55
A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgradin...
CVE-2026-1962
- EPSS 0.03%
- Veröffentlicht 05.02.2026 20:32:08
- Zuletzt bearbeitet 12.02.2026 17:29:38
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be ini...
CVE-2026-1898
- EPSS 0.02%
- Veröffentlicht 05.02.2026 00:32:09
- Zuletzt bearbeitet 10.02.2026 21:46:48
A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It is possible to initiate the att...
CVE-2026-1897
- EPSS 0.01%
- Veröffentlicht 05.02.2026 00:02:07
- Zuletzt bearbeitet 10.02.2026 17:47:03
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attac...
CVE-2026-1896
- EPSS 0.02%
- Veröffentlicht 04.02.2026 23:32:08
- Zuletzt bearbeitet 10.02.2026 17:45:59
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation...
CVE-2026-1895
- EPSS 0.02%
- Veröffentlicht 04.02.2026 23:15:55
- Zuletzt bearbeitet 23.02.2026 10:16:23
A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remot...
CVE-2026-1894
- EPSS 0.01%
- Veröffentlicht 04.02.2026 22:32:08
- Zuletzt bearbeitet 11.02.2026 19:08:27
A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument item.cardId/item.checklistId/card.boardId results in improper...
- EPSS 0.02%
- Veröffentlicht 04.02.2026 22:15:58
- Zuletzt bearbeitet 10.02.2026 17:45:33
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improp...
CVE-2025-65782
- EPSS 0.04%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 23.12.2025 18:08:12
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in ...