Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Wekan — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in Wekan, with AI-generated Chinese analysis, references, and POCs.

This page details known vulnerabilities associated with the Wekan open-source kanban board application, categorized by weakness type and relevant security tags. It aggregates historical security data to provide a comprehensive view of the risks impacting this specific product line. The content covers a wide range of vulnerability classes, including authentication bypasses, cross-site scripting (XSS), and insecure direct object references, spanning from the project's early development phases through recent updates. Readers can utilize this resource to track vendor advisories as they are released, gaining insight into how the Wekan team responds to security reports. It also allows users to understand specific weakness classes in the context of web-based collaboration tools, helping developers identify common pitfalls in similar applications. Furthermore, the page serves as a historical record, enabling security professionals and administrators to look up the product's vulnerability history to assess long-term security trends and the effectiveness of previous remediation efforts. This information is critical for organizations relying on Wekan, as it helps them prioritize patches and strengthen their internal security posture against known exploit vectors. By consolidating this data, the page offers a transparent look at the security landscape surrounding Wekan, supporting informed decision-making for both maintainers and end-users who need to evaluate the trustworthiness of the software stack in their deployment environments.

Vendor: Wekan Team

CVE ID Title CVSS Severity Published
CVE-2026-68901 WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of Service CWE-476 6.5 Medium 2026-08-19
CVE-2026-68900 Wekan: Stored XSS in HTML board exports through a card-title second parse CWE-79 7.6 High 2026-08-19
CVE-2026-68899 Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback CWE-434 8.7 High 2026-08-19
CVE-2026-68561 Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule CWE-269 8.8 High 2026-08-19
CVE-2026-68560 Wekan:hell Injection in External Antivirus Scanner Path via asyncExec CWE-78 7.7 High 2026-08-19
CVE-2026-68558 Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) CWE-918 8.5 High 2026-08-19
CVE-2026-68559 Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`) CWE-639 6.5 Medium 2026-08-19
CVE-2026-55652 Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin) CWE-287 9.8 Critical 2026-07-15
CVE-2026-55234 Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule) CWE-284 8.5 High 2026-07-15
CVE-2026-53447 Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID CWE-639 6.5 Medium 2026-07-15
CVE-2026-52893 Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook CWE-287 - - 2026-07-15
CVE-2026-53444 Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin CWE-269 - - 2026-07-15
CVE-2026-53445 Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boards CWE-862 - - 2026-07-15
CVE-2026-53446 Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs CWE-918 - - 2026-07-15
CVE-2026-52892 Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops) CWE-862 6.5 Medium 2026-07-15
CVE-2026-52891 Wekan: Shell Injection via Avatar Upload CWE-78 9.9 Critical 2026-07-15
CVE-2026-52890 Wekan: Arbitrary file read and server DoS via attachment versions.original.path CWE-22 7.1 High 2026-07-15
CVE-2026-59154 Wekan: Checklist direct DDP updates can write checklist data into private boards CWE-863 4.3 Medium 2026-07-10
CVE-2026-41455 WeKan < 8.35 SSRF via Webhook URL CWE-918 8.5 High 2026-04-22
CVE-2026-41454 WeKan < 8.35 Missing Authorization via Integration REST API CWE-862 8.3 High 2026-04-22
CVE-2026-30847 Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session Tokens CWE-200 6.5 - 2026-03-06
CVE-2026-30846 Wekan Exposes All Global Webhook Integrations through globalwebhooks Publication CWE-306 7.5 - 2026-03-06
CVE-2026-30845 Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication CWE-200 7.5 - 2026-03-06
CVE-2026-30844 Wekan Vulnerable to SSRF through Lack of Validation or Filtering in Attachment URL Loading CWE-918 9.1 - 2026-03-06
CVE-2026-30843 Wekan has Cross-Board IDOR in Custom Fields Update Endpoints CWE-639 6.5 - 2026-03-06
CVE-2026-2209 WeKan Custom Translation translationBody.js setCreateTranslation improper authorization CWE-285 6.3 Medium 2026-02-08
CVE-2026-2208 WeKan Rules rules.js RulesBleed authorization CWE-862 4.3 Medium 2026-02-08
CVE-2026-2207 WeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosure CWE-200 5.3 Medium 2026-02-08
CVE-2026-2206 WeKan Administrative Repair fixDuplicateLists.js FixDuplicateBleed access control CWE-284 6.3 Medium 2026-02-08
CVE-2026-2205 WeKan Meteor Publication cards.js CardPubSubBleed information disclosure CWE-200 4.3 Medium 2026-02-08

All 50 known CVE vulnerabilities affecting Wekan with full Chinese analysis, references, and POCs where available.