Known vulnerabilities in Wekan 10.54 - page 3

Software: Wekan
Version: 10.54
Software CPE: cpe:2.3:a:wekan.github.io:wekan:*:*:*:*:*:*:*:*
Total vulnerabilities: 56
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Wekan version 10.54 Wekan 10.54 is affected by 56 vulnerabilities: 4 high, 11 medium, 41 low Critical High Medium Low

Vulnerabilities (56)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145023 - Incorrect Authorization
CWE-863 Low
No
No
11.07 25.08.2026 SB2026082523
#VU145022 - Incorrect Authorization
CWE-863 Low
No
No
11.07 25.08.2026 SB2026082523
#VU144220 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
10.92 18.08.2026 SB2026081867
#VU144219 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
10.92 18.08.2026 SB2026081867
#VU144218 - Incorrect Authorization
CWE-863 Low
No
No
10.92 18.08.2026 SB2026081867
#VU144217 - Unverified Ownership
CWE-283 Low
No
No
10.92 18.08.2026 SB2026081867
#VU144216 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
10.92 18.08.2026 SB2026081867
#VU144215 - Improper Neutralization of Special Elements in Data Query Logic
CWE-943 Low
No
No
10.82 18.08.2026 SB2026081866
#VU144213 - Incorrect Authorization
CWE-863 Low
No
No
10.74 18.08.2026 SB2026081864
#VU144212 - Missing Authorization
CWE-862 Low
No
No
10.74 18.08.2026 SB2026081864
#VU144211 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
10.74 18.08.2026 SB2026081864
#VU144210 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
10.74 18.08.2026 SB2026081864
#VU144208 - Information Exposure Through Timing Discrepancy
CWE-208 Medium
No
No
10.59 18.08.2026 SB2026081863
#VU144209 - Improper Restriction of Excessive Authentication Attempts
CWE-307 High
No
No
10.59 18.08.2026 SB2026081863
#VU140828 - Improper input validation
CWE-20 Low
No
No
10.57 03.08.2026 SB2026080393
#VU140827 - Server-Side Request Forgery (SSRF)
CWE-918 Low
No
No
10.57 03.08.2026 SB2026080393


Showing elements 41 - 60 out of 56