Wekan Project
30 known vulnerabilities
Top Products
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forg
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publi
A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public
A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/meth
A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permis
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checkl
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checkl
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully vali
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied userna
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the
A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attac
A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/m
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMig
A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the com
A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model
Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' page
Frequently Asked Questions
How many CVEs affect Wekan Project?
Wekan Project has 30 CVE records in our database, including 1 critical and 7 high severity vulnerabilities.
What are the most severe Wekan Project vulnerabilities?
Wekan Project has 1 critical severity (CVSS 9.0+) and 7 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Wekan Project vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Wekan Project products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Wekan Project Vulnerabilities
CyberStrike scans your infrastructure for Wekan Project vulnerabilities and provides real-time remediation guidance.
Get Started