Known vulnerabilities in Wekan 10.93

Software: Wekan
Version: 10.93
Software CPE: cpe:2.3:a:wekan.github.io:wekan:*:*:*:*:*:*:*:*
Total vulnerabilities: 43
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Wekan version 10.93 Wekan 10.93 is affected by 43 vulnerabilities: 3 high, 11 medium, 29 low Critical High Medium Low

Vulnerabilities (43)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150021 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150020 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150019 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150016 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150017 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150018 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150013 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150014 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150015 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150012 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150011 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150010 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150009 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150008 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150007 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 High
No
No
11.65 15.09.2026 SB2026091568
#VU150006 - Missing Authorization
CWE-862 High
No
No
11.65 15.09.2026 SB2026091568
#VU150005 - Missing Authorization
CWE-862 Medium
No
No
11.65 15.09.2026 SB2026091568
#VU150004 - Missing Authorization
CWE-862 Medium
No
No
11.65 15.09.2026 SB2026091568
#VU147310 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
11.41 07.09.2026 SB2026091566
#VU147307 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
11.15 07.09.2026 SB2026090797


Showing elements 1 - 20 out of 43