CVE-2025-65779: High severity wekan/wekan vulnerability
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65779?
CVE-2025-65779 is considered a moderate severity vulnerability as it allows unauthenticated attackers to reorder boards in Wekan.
How do I fix CVE-2025-65779?
To fix CVE-2025-65779, update Wekan to version 18.16 or higher, where the vulnerability has been patched.
What versions of Wekan are affected by CVE-2025-65779?
CVE-2025-65779 affects Wekan versions up to and including 18.15.
What are the consequences of exploiting CVE-2025-65779?
Exploiting CVE-2025-65779 allows an attacker to arbitrarily reorder boards, potentially disrupting user workflows.
Is authentication required to exploit CVE-2025-65779?
No, CVE-2025-65779 can be exploited by unauthenticated attackers due to the lack of user verification when updating board values.