{"schema_version":1,"title":"WeKan vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in WeKan: 0 in the last 7 days and 11 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55652, was published on 15 July 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/wekan","json_url":"https://junglewise.ai/threats/vendors/wekan.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/wekan","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":8,"all_time":23,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":23},"latest":[{"cve":"CVE-2026-55652","cvss":9.8,"slug":"cve-2026-55652-wekan-authentication-bypass-via-x-forwarded-for-spoofing-in","title":"Wekan authentication bypass via X-Forwarded-For spoofing in header-login","severity":"critical","exploited":false,"published_at":"2026-07-15T22:17:26.293+00:00","url":"https://junglewise.ai/threats/cve-2026-55652-wekan-authentication-bypass-via-x-forwarded-for-spoofing-in"},{"cve":"CVE-2026-55234","cvss":8.5,"slug":"cve-2026-55234-wekan-broken-access-control-in-ddp-update-rules","title":"Wekan broken access control in DDP update rules","severity":"high","exploited":false,"published_at":"2026-07-15T22:17:25.88+00:00","url":"https://junglewise.ai/threats/cve-2026-55234-wekan-broken-access-control-in-ddp-update-rules"},{"cve":"CVE-2026-53447","cvss":6.5,"slug":"cve-2026-53447-wekan-missing-authorization-in-cloneboard-method","title":"Wekan missing authorization in cloneBoard method","severity":"medium","exploited":false,"published_at":"2026-07-15T22:17:17.24+00:00","url":"https://junglewise.ai/threats/cve-2026-53447-wekan-missing-authorization-in-cloneboard-method"},{"cve":"CVE-2026-53446","cvss":6.2,"slug":"cve-2026-53446-wekan-ssrf-in-webhook-integration-urls","title":"Wekan SSRF in webhook integration URLs","severity":"info","exploited":false,"published_at":"2026-07-15T22:17:17.103+00:00","url":"https://junglewise.ai/threats/cve-2026-53446-wekan-ssrf-in-webhook-integration-urls"},{"cve":"CVE-2026-53445","cvss":7.1,"slug":"cve-2026-53445-wekan-missing-authorization-in-copyboard-ddp-method","title":"Wekan missing authorization in copyBoard DDP method","severity":"info","exploited":false,"published_at":"2026-07-15T22:17:16.973+00:00","url":"https://junglewise.ai/threats/cve-2026-53445-wekan-missing-authorization-in-copyboard-ddp-method"},{"cve":"CVE-2026-53444","cvss":7.6,"slug":"cve-2026-53444-wekan-privilege-escalation-in-oidc-meteor-methods","title":"Wekan privilege escalation in OIDC Meteor methods","severity":"info","exploited":false,"published_at":"2026-07-15T22:17:16.84+00:00","url":"https://junglewise.ai/threats/cve-2026-53444-wekan-privilege-escalation-in-oidc-meteor-methods"},{"cve":"CVE-2026-52893","cvss":9.2,"slug":"cve-2026-52893-wekan-account-takeover-via-oidc-account-merging","title":"Wekan account takeover via OIDC account merging","severity":"info","exploited":false,"published_at":"2026-07-15T22:17:16.71+00:00","url":"https://junglewise.ai/threats/cve-2026-52893-wekan-account-takeover-via-oidc-account-merging"},{"cve":"CVE-2026-52892","cvss":6.5,"slug":"cve-2026-52892-wekan-authorization-bypass-for-custom-fields-in-rest-api","title":"Wekan authorization bypass for custom fields in REST API","severity":"medium","exploited":false,"published_at":"2026-07-15T22:17:16.58+00:00","url":"https://junglewise.ai/threats/cve-2026-52892-wekan-authorization-bypass-for-custom-fields-in-rest-api"},{"cve":"CVE-2026-52891","cvss":9.9,"slug":"cve-2026-52891-wekan-shell-command-injection-in-avatar-upload","title":"Wekan shell command injection in avatar upload","severity":"critical","exploited":false,"published_at":"2026-07-15T22:17:16.45+00:00","url":"https://junglewise.ai/threats/cve-2026-52891-wekan-shell-command-injection-in-avatar-upload"},{"cve":"CVE-2026-52890","cvss":7.1,"slug":"cve-2026-52890-wekan-path-traversal-and-dos-via-attachment-insertion","title":"Wekan path traversal and DoS via attachment insertion","severity":"high","exploited":false,"published_at":"2026-07-15T22:17:16.31+00:00","url":"https://junglewise.ai/threats/cve-2026-52890-wekan-path-traversal-and-dos-via-attachment-insertion"},{"cve":"CVE-2026-59154","cvss":4.3,"slug":"cve-2026-59154-wekan-authorization-bypass-in-checklists-and-checklistitems","title":"Wekan authorization bypass in Checklists and ChecklistItems","severity":"medium","exploited":false,"published_at":"2026-07-10T17:17:02.113+00:00","url":"https://junglewise.ai/threats/cve-2026-59154-wekan-authorization-bypass-in-checklists-and-checklistitems"},{"cve":"CVE-2026-41455","cvss":8.5,"epss":0.0003,"slug":"cve-2026-41455-wekan-ssrf-and-unauthorized-comment-modification-in-webhooks","title":"WeKan SSRF and unauthorized comment modification in webhooks","severity":"high","exploited":false,"published_at":"2026-04-22T22:16:32.677+00:00","url":"https://junglewise.ai/threats/cve-2026-41455-wekan-ssrf-and-unauthorized-comment-modification-in-webhooks"},{"cve":"CVE-2026-41454","cvss":8.3,"epss":0.0027,"slug":"cve-2026-41454-wekan-missing-authorization-in-integration-rest-api","title":"WeKan missing authorization in Integration REST API","severity":"high","exploited":false,"published_at":"2026-04-22T22:16:32.497+00:00","url":"https://junglewise.ai/threats/cve-2026-41454-wekan-missing-authorization-in-integration-rest-api"},{"cve":"CVE-2026-25859","cvss":8.8,"epss":0.0034,"slug":"cve-2026-25859-wekan-incorrect-authorization-in-migration-functionality","title":"WeKan incorrect authorization in migration functionality","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:02.91+00:00","url":"https://junglewise.ai/threats/cve-2026-25859-wekan-incorrect-authorization-in-migration-functionality"},{"cve":"CVE-2026-25568","cvss":4.3,"epss":0.0019,"slug":"cve-2026-25568-wekan-authorization-bypass-in-allowprivateonly-setting","title":"WeKan authorization bypass in allowPrivateOnly setting","severity":"medium","exploited":false,"published_at":"2026-02-07T22:16:02.467+00:00","url":"https://junglewise.ai/threats/cve-2026-25568-wekan-authorization-bypass-in-allowprivateonly-setting"},{"cve":"CVE-2026-25567","cvss":4.3,"epss":0.0025,"slug":"cve-2026-25567-wekan-idor-in-card-comment-creation-api","title":"WeKan IDOR in card comment creation API","severity":"medium","exploited":false,"published_at":"2026-02-07T22:16:02.333+00:00","url":"https://junglewise.ai/threats/cve-2026-25567-wekan-idor-in-card-comment-creation-api"},{"cve":"CVE-2026-25566","cvss":5.4,"epss":0.0022,"slug":"cve-2026-25566-wekan-incorrect-authorization-in-cross-board-card-move-logic","title":"WeKan incorrect authorization in cross-board card move logic","severity":"medium","exploited":false,"published_at":"2026-02-07T22:16:02.19+00:00","url":"https://junglewise.ai/threats/cve-2026-25566-wekan-incorrect-authorization-in-cross-board-card-move-logic"},{"cve":"CVE-2026-25565","cvss":6.5,"epss":0.0028,"slug":"cve-2026-25565-wekan-incorrect-authorization-in-card-update-api","title":"WeKan incorrect authorization in card update API","severity":"medium","exploited":false,"published_at":"2026-02-07T22:16:02.043+00:00","url":"https://junglewise.ai/threats/cve-2026-25565-wekan-incorrect-authorization-in-card-update-api"},{"cve":"CVE-2026-25564","cvss":7.5,"epss":0.0028,"slug":"cve-2026-25564-wekan-idor-in-checklist-creation-and-deletion-routes","title":"WeKan IDOR in checklist creation and deletion routes","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:01.903+00:00","url":"https://junglewise.ai/threats/cve-2026-25564-wekan-idor-in-checklist-creation-and-deletion-routes"},{"cve":"CVE-2026-25563","cvss":7.5,"epss":0.0028,"slug":"cve-2026-25563-wekan-idor-in-checklist-creation","title":"WeKan IDOR in checklist creation","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:01.767+00:00","url":"https://junglewise.ai/threats/cve-2026-25563-wekan-idor-in-checklist-creation"},{"cve":"CVE-2026-25562","cvss":4.3,"epss":0.0029,"slug":"cve-2026-25562-wekan-information-disclosure-in-attachments-publication","title":"WeKan information disclosure in attachments publication","severity":"medium","exploited":false,"published_at":"2026-02-07T22:16:01.627+00:00","url":"https://junglewise.ai/threats/cve-2026-25562-wekan-information-disclosure-in-attachments-publication"},{"cve":"CVE-2026-25561","cvss":7.5,"epss":0.0028,"slug":"cve-2026-25561-wekan-authorization-weakness-in-attachment-upload-api","title":"WeKan authorization weakness in attachment upload API","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:01.49+00:00","url":"https://junglewise.ai/threats/cve-2026-25561-wekan-authorization-weakness-in-attachment-upload-api"},{"cve":"CVE-2026-25560","cvss":9.8,"epss":0.0065,"slug":"cve-2026-25560-wekan-ldap-filter-injection-in-ldap-authentication","title":"WeKan LDAP filter injection in LDAP authentication","severity":"critical","exploited":false,"published_at":"2026-02-07T22:16:01.347+00:00","url":"https://junglewise.ai/threats/cve-2026-25560-wekan-ldap-filter-injection-in-ldap-authentication"}],"vendor":{"hub":true,"name":"WeKan","slug":"wekan","homepage":"https://wekan.github.io/","description":"WeKan is an open-source kanban board software organization.","url":"https://junglewise.ai/threats/vendors/wekan"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":2,"exploited":0,"vulnerabilities":10},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-52891","cvss":9.9,"slug":"cve-2026-52891-wekan-shell-command-injection-in-avatar-upload","title":"Wekan shell command injection in avatar upload","severity":"critical","exploited":false,"published_at":"2026-07-15T22:17:16.45+00:00","url":"https://junglewise.ai/threats/cve-2026-52891-wekan-shell-command-injection-in-avatar-upload"},{"cve":"CVE-2026-25560","cvss":9.8,"epss":0.0065,"slug":"cve-2026-25560-wekan-ldap-filter-injection-in-ldap-authentication","title":"WeKan LDAP filter injection in LDAP authentication","severity":"critical","exploited":false,"published_at":"2026-02-07T22:16:01.347+00:00","url":"https://junglewise.ai/threats/cve-2026-25560-wekan-ldap-filter-injection-in-ldap-authentication"},{"cve":"CVE-2026-55652","cvss":9.8,"slug":"cve-2026-55652-wekan-authentication-bypass-via-x-forwarded-for-spoofing-in","title":"Wekan authentication bypass via X-Forwarded-For spoofing in header-login","severity":"critical","exploited":false,"published_at":"2026-07-15T22:17:26.293+00:00","url":"https://junglewise.ai/threats/cve-2026-55652-wekan-authentication-bypass-via-x-forwarded-for-spoofing-in"},{"cve":"CVE-2026-25859","cvss":8.8,"epss":0.0034,"slug":"cve-2026-25859-wekan-incorrect-authorization-in-migration-functionality","title":"WeKan incorrect authorization in migration functionality","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:02.91+00:00","url":"https://junglewise.ai/threats/cve-2026-25859-wekan-incorrect-authorization-in-migration-functionality"},{"cve":"CVE-2026-41455","cvss":8.5,"epss":0.0003,"slug":"cve-2026-41455-wekan-ssrf-and-unauthorized-comment-modification-in-webhooks","title":"WeKan SSRF and unauthorized comment modification in webhooks","severity":"high","exploited":false,"published_at":"2026-04-22T22:16:32.677+00:00","url":"https://junglewise.ai/threats/cve-2026-41455-wekan-ssrf-and-unauthorized-comment-modification-in-webhooks"},{"cve":"CVE-2026-55234","cvss":8.5,"slug":"cve-2026-55234-wekan-broken-access-control-in-ddp-update-rules","title":"Wekan broken access control in DDP update rules","severity":"high","exploited":false,"published_at":"2026-07-15T22:17:25.88+00:00","url":"https://junglewise.ai/threats/cve-2026-55234-wekan-broken-access-control-in-ddp-update-rules"},{"cve":"CVE-2026-41454","cvss":8.3,"epss":0.0027,"slug":"cve-2026-41454-wekan-missing-authorization-in-integration-rest-api","title":"WeKan missing authorization in Integration REST API","severity":"high","exploited":false,"published_at":"2026-04-22T22:16:32.497+00:00","url":"https://junglewise.ai/threats/cve-2026-41454-wekan-missing-authorization-in-integration-rest-api"},{"cve":"CVE-2026-25564","cvss":7.5,"epss":0.0028,"slug":"cve-2026-25564-wekan-idor-in-checklist-creation-and-deletion-routes","title":"WeKan IDOR in checklist creation and deletion routes","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:01.903+00:00","url":"https://junglewise.ai/threats/cve-2026-25564-wekan-idor-in-checklist-creation-and-deletion-routes"},{"cve":"CVE-2026-25563","cvss":7.5,"epss":0.0028,"slug":"cve-2026-25563-wekan-idor-in-checklist-creation","title":"WeKan IDOR in checklist creation","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:01.767+00:00","url":"https://junglewise.ai/threats/cve-2026-25563-wekan-idor-in-checklist-creation"},{"cve":"CVE-2026-25561","cvss":7.5,"epss":0.0028,"slug":"cve-2026-25561-wekan-authorization-weakness-in-attachment-upload-api","title":"WeKan authorization weakness in attachment upload API","severity":"high","exploited":false,"published_at":"2026-02-07T22:16:01.49+00:00","url":"https://junglewise.ai/threats/cve-2026-25561-wekan-authorization-weakness-in-attachment-upload-api"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Wekan","slug":"wekan","vulnerabilities":23,"url":"https://junglewise.ai/threats/technologies/wekan"}]}