Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WeKan — Vulnerabilities & Security Advisories 35

Browse all 35 CVE security advisories affecting WeKan. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WeKan serves as an open-source Kanban board application for team project management. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, contributing to its 17 recorded CVEs. Notable security characteristics include its self-hosted nature, which allows organizations to maintain control over their data but requires diligent patch management. While no major public security incidents have been widely documented, the consistent discovery of vulnerabilities in areas such as authentication and file handling underscores the importance of regular security updates for deployments handling sensitive project information.

Top products by WeKan: WeKan
CVE ID Title CVSS Severity Published
CVE-2026-68901 WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of Service — wekan CWE-476 6.5 Medium 2026-08-19
CVE-2026-68900 Wekan: Stored XSS in HTML board exports through a card-title second parse — wekan CWE-79 7.6 High 2026-08-19
CVE-2026-68899 Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback — wekan CWE-434 8.7 High 2026-08-19
CVE-2026-68561 Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule — wekan CWE-269 8.8 High 2026-08-19
CVE-2026-68560 Wekan:hell Injection in External Antivirus Scanner Path via asyncExec — wekan CWE-78 7.7 High 2026-08-19
CVE-2026-68558 Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) — wekan CWE-918 8.5 High 2026-08-19
CVE-2026-68559 Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`) — wekan CWE-639 6.5 Medium 2026-08-19
CVE-2026-55652 Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin) — wekan CWE-287 9.8 Critical 2026-07-15
CVE-2026-55234 Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule) — wekan CWE-284 8.5 High 2026-07-15
CVE-2026-53447 Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID — wekan CWE-639 6.5 Medium 2026-07-15
CVE-2026-52893 Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook — wekan CWE-287 - - 2026-07-15
CVE-2026-53444 Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin — wekan CWE-269 - - 2026-07-15
CVE-2026-53445 Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boards — wekan CWE-862 - - 2026-07-15
CVE-2026-53446 Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs — wekan CWE-918 - - 2026-07-15
CVE-2026-52892 Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops) — wekan CWE-862 6.5 Medium 2026-07-15
CVE-2026-52891 Wekan: Shell Injection via Avatar Upload — wekan CWE-78 9.9 Critical 2026-07-15
CVE-2026-52890 Wekan: Arbitrary file read and server DoS via attachment versions.original.path — wekan CWE-22 7.1 High 2026-07-15
CVE-2026-59154 Wekan: Checklist direct DDP updates can write checklist data into private boards — wekan CWE-863 4.3 Medium 2026-07-10
CVE-2026-41455 WeKan < 8.35 SSRF via Webhook URL — wekan CWE-918 8.5 High 2026-04-22
CVE-2026-41454 WeKan < 8.35 Missing Authorization via Integration REST API — wekan CWE-862 8.3 High 2026-04-22
CVE-2026-30847 Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session Tokens — Wekan CWE-200 6.5 - 2026-03-06
CVE-2026-30846 Wekan Exposes All Global Webhook Integrations through globalwebhooks Publication — Wekan CWE-306 7.5 - 2026-03-06
CVE-2026-30845 Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication — Wekan CWE-200 7.5 - 2026-03-06
CVE-2026-30844 Wekan Vulnerable to SSRF through Lack of Validation or Filtering in Attachment URL Loading — Wekan CWE-918 9.1 - 2026-03-06
CVE-2026-30843 Wekan has Cross-Board IDOR in Custom Fields Update Endpoints — Wekan CWE-639 6.5 - 2026-03-06
CVE-2026-25859 WeKan < 8.20 Migration Functionality Insufficient Permission Checks — WeKan CWE-863 7.1AI High AI 2026-02-07
CVE-2026-25568 WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass — WeKan CWE-863 6.5AI Medium AI 2026-02-07
CVE-2026-25567 WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId — WeKan CWE-639 6.5AI Medium AI 2026-02-07
CVE-2026-25566 WeKan < 8.19 Cross-board Card Move Without Destination Authorization — WeKan CWE-863 3.3AI Low AI 2026-02-07
CVE-2026-25565 WeKan < 8.19 Read-only Board Roles Can Update Cards — WeKan CWE-863 4.3AI Medium AI 2026-02-07

This page lists every published CVE security advisory associated with WeKan. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.