Known vulnerabilities in Wekan 11.01

Software: Wekan
Version: 11.01
Software CPE: cpe:2.3:a:wekan.github.io:wekan:*:*:*:*:*:*:*:*
Total vulnerabilities: 47
Public exploits: 8
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Wekan version 11.01 Wekan 11.01 is affected by 47 vulnerabilities: 3 high, 13 medium, 31 low Critical High Medium Low

Vulnerabilities (47)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150021 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150020 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150019 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150016 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150017 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150018 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150013 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150014 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150015 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150012 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150011 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150010 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150009 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150008 - Incorrect Authorization
CWE-863 Low
No
No
11.77 15.09.2026 SB2026091569
#VU150007 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 High
No
No
11.65 15.09.2026 SB2026091568
#VU150006 - Missing Authorization
CWE-862 High
No
No
11.65 15.09.2026 SB2026091568
#VU150005 - Missing Authorization
CWE-862 Medium
No
No
11.65 15.09.2026 SB2026091568
#VU150004 - Missing Authorization
CWE-862 Medium
No
No
11.65 15.09.2026 SB2026091568
#VU147310 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
11.41 07.09.2026 SB2026091566
#VU147309 - Improper Control of Interaction Frequency
CWE-799 Medium
No
No
11.15 07.09.2026 SB2026090797


Showing elements 1 - 20 out of 47