wekan
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 15, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Wekan: Stored XSS in HTML board exports through a card-title second parse
Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback
Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule
Wekan:hell Injection in External Antivirus Scanner Path via asyncExec
Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)
Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`)
Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)
Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin
WeKan < 8.35 SSRF via Webhook URL
WeKan < 8.35 Missing Authorization via Integration REST API
Monitor wekan in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.