wekan_project CVE Vulnerabilities & Metrics

Focus on wekan_project vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About wekan_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wekan_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wekan_project CVEs: 10
Earliest CVE date: 26 Jun 2018, 16:29 UTC
Latest CVE date: 15 Dec 2025, 14:15 UTC

Latest CVE reference: CVE-2025-65782

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 5

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wekan_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.53

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 2
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS wekan_project CVEs

These are the five CVEs with the highest CVSS scores for wekan_project, sorted by severity first and recency.

All CVEs for wekan_project

CVE-2025-65782 wekan_project vulnerability CVSS: 0 15 Dec 2025, 14:15 UTC

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in vote.positive / vote.negative arrays, enabling vote forgery and unauthorized voting.

CVE-2025-65781 wekan_project vulnerability CVSS: 0 15 Dec 2025, 14:15 UTC

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.

CVE-2025-65780 wekan_project vulnerability CVSS: 0 15 Dec 2025, 14:15 UTC

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privilege escalation and unauthorized access to other teams/orgs.

CVE-2025-65779 wekan_project vulnerability CVSS: 0 15 Dec 2025, 14:15 UTC

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

CVE-2025-65778 wekan_project vulnerability CVSS: 0 15 Dec 2025, 14:15 UTC

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions.

CVE-2023-28485 wekan_project vulnerability CVSS: 0 26 Jun 2023, 16:15 UTC

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.

CVE-2023-31779 wekan_project vulnerability CVSS: 0 22 May 2023, 13:15 UTC

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

CVE-2021-20654 wekan_project vulnerability CVSS: 3.5 10 Feb 2021, 09:15 UTC

Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.

CVE-2021-3309 wekan_project vulnerability CVSS: 6.8 26 Jan 2021, 21:15 UTC

packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,

CVE-2018-1000549 wekan_project vulnerability CVSS: 5.0 26 Jun 2018, 16:29 UTC

Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can result in A remote attacker could perform a brute force attack to obtain valid usernames and email addresses.. This attack appear to be exploitable via HTTP Request.