Browse all 35 CVE security advisories affecting WeKan. AI-powered Chinese analysis, POCs, and references for each vulnerability.
WeKan serves as an open-source Kanban board application for team project management. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, contributing to its 17 recorded CVEs. Notable security characteristics include its self-hosted nature, which allows organizations to maintain control over their data but requires diligent patch management. While no major public security incidents have been widely documented, the consistent discovery of vulnerabilities in areas such as authentication and file handling underscores the importance of regular security updates for deployments handling sensitive project information.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-25564 | WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship Validation — WeKan CWE-639 | 6.5AI | Medium AI | 2026-02-07 |
| CVE-2026-25563 | WeKan < 8.19 Checklist Creation Cross-Board IDOR — WeKan CWE-639 | 6.5AI | Medium AI | 2026-02-07 |
| CVE-2026-25562 | WeKan < 8.19 Attachments Publication Information Disclosure — WeKan CWE-203 | 5.3AI | Medium AI | 2026-02-07 |
| CVE-2026-25561 | WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass — WeKan CWE-863 | 7.5AI | High AI | 2026-02-07 |
| CVE-2026-25560 | WeKan < 8.19 LDAP Authentication Filter Injection — WeKan CWE-90 | 7.5AI | High AI | 2026-02-07 |
This page lists every published CVE security advisory associated with WeKan. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.