Known vulnerabilities in Wekan 10.68 - page 2

Software: Wekan
Version: 10.68
Software CPE: cpe:2.3:a:wekan.github.io:wekan:*:*:*:*:*:*:*:*
Total vulnerabilities: 53
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Wekan version 10.68 Wekan 10.68 is affected by 53 vulnerabilities: 3 high, 11 medium, 39 low Critical High Medium Low

Vulnerabilities (53)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU147308 - Authorization Bypass Through User-Controlled SQL Primary Key
CWE-566 Medium
No
No
11.15 07.09.2026 SB2026090797
#VU147307 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
11.15 07.09.2026 SB2026090797
#VU146569 - Sensitive Cookie Without 'HttpOnly' Flag
CWE-1004 Low
Public exploit available
No
11.27 01.09.2026 SB2026090142
#VU146545 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
Public exploit available
No
11.27 01.09.2026 SB2026090142
#VU146544 - Improper Neutralization of Special Elements in Data Query Logic
CWE-943 Medium
Public exploit available
No
11.27 01.09.2026 SB2026090142
#VU145038 - Improper Authentication
CWE-287 Low
No
No
11.11 25.08.2026 SB2026082526
#VU145037 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.11 25.08.2026 SB2026082526
#VU145036 - Authorization Bypass Through User-Controlled Key
CWE-639 Medium
No
No
11.11 25.08.2026 SB2026082526
#VU145035 - Inefficient Regular Expression Complexity
CWE-1333 Low
No
No
11.11 25.08.2026 SB2026082526
#VU145034 - Missing Authentication for Critical Function
CWE-306 Medium
No
No
11.11 25.08.2026 SB2026082526
#VU145031 - Improper Access Control
CWE-284 Medium
No
No
11.11 25.08.2026 SB2026082526
#VU145032 - Resource exhaustion
CWE-400 Medium
No
No
11.11 25.08.2026 SB2026082526
#VU145030 - Missing Authentication for Critical Function
CWE-306 High
No
No
11.10 25.08.2026 SB2026082525
#VU145029 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.08 25.08.2026 SB2026082524
#VU145028 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.08 25.08.2026 SB2026082524
#VU145027 - Improper Authorization
CWE-285 Low
No
No
11.08 25.08.2026 SB2026082524
#VU145026 - Improper Authorization
CWE-285 Low
No
No
11.08 25.08.2026 SB2026082524
#VU145025 - Information Exposure Through an Error Message
CWE-209 Low
No
No
11.08 25.08.2026 SB2026082524
#VU145024 - Incorrect Authorization
CWE-863 Low
No
No
11.08 25.08.2026 SB2026082524
#VU145023 - Incorrect Authorization
CWE-863 Low
No
No
11.07 25.08.2026 SB2026082523


Showing elements 21 - 40 out of 53