Vulnerabilities
Vulnerable Software
Wekan Project:  >> Wekan  >> 3.22  Security Vulnerabilities
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.
CVSS Score
5.4
EPSS Score
0.006
Published
2023-05-22
Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.
CVSS Score
5.4
EPSS Score
0.008
Published
2021-02-10
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,
CVSS Score
8.1
EPSS Score
0.017
Published
2021-01-26


Contact Us

Shodan ® - All rights reserved