Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Wekan — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in Wekan, with AI-generated Chinese analysis, references, and POCs.

This page details known vulnerabilities associated with the Wekan open-source kanban board application, categorized by weakness type and relevant security tags. It aggregates historical security data to provide a comprehensive view of the risks impacting this specific product line. The content covers a wide range of vulnerability classes, including authentication bypasses, cross-site scripting (XSS), and insecure direct object references, spanning from the project's early development phases through recent updates. Readers can utilize this resource to track vendor advisories as they are released, gaining insight into how the Wekan team responds to security reports. It also allows users to understand specific weakness classes in the context of web-based collaboration tools, helping developers identify common pitfalls in similar applications. Furthermore, the page serves as a historical record, enabling security professionals and administrators to look up the product's vulnerability history to assess long-term security trends and the effectiveness of previous remediation efforts. This information is critical for organizations relying on Wekan, as it helps them prioritize patches and strengthen their internal security posture against known exploit vectors. By consolidating this data, the page offers a transparent look at the security landscape surrounding Wekan, supporting informed decision-making for both maintainers and end-users who need to evaluate the trustworthiness of the software stack in their deployment environments.

Vendor: Wekan Team

CVE ID Title CVSS Severity Published
CVE-2026-25859 WeKan < 8.20 Migration Functionality Insufficient Permission Checks CWE-863 7.1AI High AI 2026-02-07
CVE-2026-25568 WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass CWE-863 6.5AI Medium AI 2026-02-07
CVE-2026-25567 WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId CWE-639 6.5AI Medium AI 2026-02-07
CVE-2026-25566 WeKan < 8.19 Cross-board Card Move Without Destination Authorization CWE-863 3.3AI Low AI 2026-02-07
CVE-2026-25565 WeKan < 8.19 Read-only Board Roles Can Update Cards CWE-863 4.3AI Medium AI 2026-02-07
CVE-2026-25564 WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship Validation CWE-639 6.5AI Medium AI 2026-02-07
CVE-2026-25563 WeKan < 8.19 Checklist Creation Cross-Board IDOR CWE-639 6.5AI Medium AI 2026-02-07
CVE-2026-25562 WeKan < 8.19 Attachments Publication Information Disclosure CWE-203 5.3AI Medium AI 2026-02-07
CVE-2026-25561 WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass CWE-863 7.5AI High AI 2026-02-07
CVE-2026-25560 WeKan < 8.19 LDAP Authentication Filter Injection CWE-90 7.5AI High AI 2026-02-07
CVE-2026-1964 WeKan REST Endpoint boards.js BoardTitleRESTBleed access control CWE-284 4.3 Medium 2026-02-05
CVE-2026-1963 WeKan Attachment Storage attachments.js MoveStorageBleed access control CWE-284 6.3 Medium 2026-02-05
CVE-2026-1962 WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access control CWE-284 6.3 Medium 2026-02-05
CVE-2026-1898 WeKan LDAP User Sync syncUser.js SyncLDAPBleed access control CWE-284 6.3 Medium 2026-02-05
CVE-2026-1897 WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization CWE-862 4.3 Medium 2026-02-05
CVE-2026-1896 WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration MigrationBleed access control CWE-284 6.3 Medium 2026-02-04
CVE-2026-1895 WeKan Attachment Storage lists.js applyWipLimit ListWIPBleed access control CWE-284 6.3 Medium 2026-02-04
CVE-2026-1894 WeKan REST API checklistItems.js Checklist REST Bleed improper authorization CWE-285 6.3 Medium 2026-02-04
CVE-2026-1892 WeKan REST API boards.js setBoardOrgs improper authorization CWE-285 5.0 Medium 2026-02-04
CVE-2021-20654 Wekan 跨站脚本漏洞 CWE-79 6.1 - 2021-02-10

All 50 known CVE vulnerabilities affecting Wekan with full Chinese analysis, references, and POCs where available.