WeKan是WeKan团队的一款项目管理软件。 WeKan 8.36版本至9.74之前版本存在服务端请求伪造漏洞,该漏洞源于对外发webhook集成URL验证不充分,可能导致服务端请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-68561 | 8.8 HIGH | Wekan: a low-privilege board member escalates to board admin and takes over a private boar |
| CVE-2026-68899 | 8.7 HIGH | Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fall |
| CVE-2026-68560 | 7.7 HIGH | Wekan:hell Injection in External Antivirus Scanner Path via asyncExec |
| CVE-2026-68900 | 7.6 HIGH | Wekan: Stored XSS in HTML board exports through a card-title second parse |
| CVE-2026-68901 | 6.5 MEDIUM | WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to |
| CVE-2026-68559 | 6.5 MEDIUM | Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel` |
No comments yet