Vulnerabilidades em WeKan
35 resultadosAnálise Vexday
WeKan apresenta 10 vulnerabilidades registradas, nenhuma atualmente sob ataque ativo ou classificada como crítica, indicando risco moderado e estável. A fraqueza dominante (CWE-863 - Controle de Acesso Inadequado) sugere problemas estruturais em autorização, mais relevantes para ambientes internos. Não há atividade recente de divulgação, permitindo planejamento deliberado de mitigação.
CVE-2026-52891CRITICALWekan: Shell Injection via Avatar UploadEPSS 0.8%CVE-2026-25560HIGHWeKan < 8.19 LDAP Authentication Filter InjectionEPSS 0.7%CVE-2026-55652CRITICALWekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)EPSS 0.6%CVE-2026-53446MEDIUMWekan: Server-Side Request Forgery (SSRF) via webhook integration URLsEPSS 0.5%CVE-2026-52893CRITICALWekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hookEPSS 0.5%CVE-2026-52890HIGHWekan: Arbitrary file read and server DoS via attachment versions.original.pathEPSS 0.5%CVE-2026-68561HIGHWekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow ruleEPSS 0.5%CVE-2026-52892MEDIUMWekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops)EPSS 0.5%CVE-2026-68901MEDIUMWeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of ServiceEPSS 0.5%CVE-2026-68560HIGHWekan:hell Injection in External Antivirus Scanner Path via asyncExecEPSS 0.4%CVE-2026-55234HIGHWekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)EPSS 0.4%CVE-2026-53445HIGHWekan: Authorization bypass in copyBoard DDP method allows any user to copy private boardsEPSS 0.4%CVE-2026-53444HIGHWekan: Missing authorization on OIDC Meteor methods allows privilege escalation to adminEPSS 0.4%CVE-2026-68899HIGHWekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary FallbackEPSS 0.4%CVE-2026-53447MEDIUMWekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by IDEPSS 0.4%CVE-2026-68559MEDIUMWekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`)EPSS 0.4%CVE-2026-68558HIGHWekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)EPSS 0.4%CVE-2026-59154MEDIUMWekan: Checklist direct DDP updates can write checklist data into private boardsEPSS 0.4%CVE-2026-25859HIGHWeKan < 8.20 Migration Functionality Insufficient Permission ChecksEPSS 0.4%CVE-2026-30846HIGHWekan Exposes All Global Webhook Integrations through globalwebhooks PublicationEPSS 0.3%