Wekan Project
Wekan Project Wekan: vulnerabilidades y CVE
Wekan Project Wekan tiene 39 vulnerabilidades publicadas, 34 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses34
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-30847 | Crítica (9.3) | 0.41% | — | 6 mar 2026 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user documents with no field filtering, causing the ReactiveCache.getUsers()… |
| CVE-2026-30846 | Alta (8.7) | 0.60% | — | 6 mar 2026 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing… |
| CVE-2026-30845 | Media (6.9) | 0.52% | — | 6 mar 2026 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data for a board without any field filtering, exposing sensitive… |
| CVE-2026-30844 | Crítica (9.3) | 0.42% | — | 6 mar 2026 | Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. During board import in Wekan, attachment URLs from… |
| CVE-2026-30843 | Crítica (9.3) | 0.38% | — | 6 mar 2026 | Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards… |
| CVE-2026-2209 | Media (5.3) | 0.20% | — | 8 feb 2026 | A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The… |
| CVE-2026-2208 | Media (5.3) | 0.26% | — | 8 feb 2026 | A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization.… |
| CVE-2026-2207 | Media (6.9) | 0.36% | — | 8 feb 2026 | A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the component Activity Publication Handler. Executing a manipulation can… |
| CVE-2026-2206 | Media (5.3) | 0.25% | — | 8 feb 2026 | A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation… |
| CVE-2026-2205 | Media (5.3) | 0.25% | — | 8 feb 2026 | A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure.… |
| CVE-2026-25859 | Alta (7.1) | 0.54% | — | 7 feb 2026 | Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations. |
| CVE-2026-25568 | Alta (7.1) | 0.35% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled,… |
| CVE-2026-25567 | Media (5.3) | 0.35% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the… |
| CVE-2026-25566 | Alta (7.1) | 0.32% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without… |
| CVE-2026-25565 | Alta (7.1) | 0.40% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles… |
| CVE-2026-25564 | Alta (7.1) | 0.41% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied… |
| CVE-2026-25563 | Alta (7.1) | 0.41% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied… |
| CVE-2026-25562 | Media (5.3) | 0.39% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the… |
| CVE-2026-25561 | Alta (7.1) | 0.41% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and… |
| CVE-2026-25560 | Alta (8.7) | 0.89% | — | 7 feb 2026 | WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping,… |
| CVE-2026-1964 | Media (5.3) | 0.23% | — | 5 feb 2026 | A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of… |
| CVE-2026-1963 | Media (5.3) | 0.34% | — | 5 feb 2026 | A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may… |
| CVE-2026-1962 | Media (5.3) | 0.34% | — | 5 feb 2026 | A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access… |
| CVE-2026-1898 | Media (5.3) | 0.28% | — | 5 feb 2026 | A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It… |
| CVE-2026-1897 | Media (5.3) | 0.32% | — | 5 feb 2026 | A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in… |
| CVE-2026-1896 | Media (5.3) | 0.31% | — | 5 feb 2026 | A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration… |
| CVE-2026-1895 | Media (5.3) | 0.31% | — | 4 feb 2026 | A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls.… |
| CVE-2026-1894 | Media (5.3) | 0.27% | — | 4 feb 2026 | A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument… |
| CVE-2026-1892 | Baja (2.3) | 0.27% | — | 4 feb 2026 | A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument… |
| CVE-2025-65782 | Media (6.5) | 0.26% | — | 15 dic 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.