Known vulnerabilities in Wekan 10.98

Software: Wekan
Version: 10.98
Software CPE: cpe:2.3:a:wekan.github.io:wekan:*:*:*:*:*:*:*:*
Total vulnerabilities: 42
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Wekan version 10.98 Wekan 10.98 is affected by 42 vulnerabilities: 3 high, 10 medium, 29 low Critical High Medium Low

Vulnerabilities (42)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150021 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150020 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150019 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150016 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150017 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150018 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150013 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150014 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150015 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150012 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150011 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150010 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150009 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150008 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150007 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 High
No
No
11.65 15.09.2026 SB2026091568
#VU150006 - Missing Authorization
CWE-862 High
No
No
11.65 15.09.2026 SB2026091568
#VU150005 - Missing Authorization
CWE-862 Medium
No
No
11.65 15.09.2026 SB2026091568
#VU150004 - Missing Authorization
CWE-862 Medium
No
No
11.65 15.09.2026 SB2026091568
#VU147310 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
11.41 07.09.2026 SB2026091566
#VU147308 - Authorization Bypass Through User-Controlled SQL Primary Key
CWE-566 Medium
No
No
11.15 07.09.2026 SB2026090797


Showing elements 1 - 20 out of 42