A vulnerability has been found in WeKan up to 8.20 and classified as problematic. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-2208. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the component Activity Publication Handler. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-2207. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2026-2206. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-2205. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in WeKan up to 8.18. Affected by this issue is some unknown functionality of the file server/publications/attachments.js of the component Attachment Metadata Handler. This manipulation causes information exposure through discrepancy.
This vulnerability is tracked as CVE-2026-25562. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in WeKan up to 8.18. Affected by this vulnerability is an unknown functionality of the file models/cardComments.js of the component Card Comment Creation API. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-25567. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in WeKan up to 8.18. Affected is an unknown function of the file models/cards.js of the component Card Move Handler. The manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-25566. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in WeKan up to 8.18. This impacts an unknown function of the component Update API. Executing a manipulation can lead to incorrect authorization.
The identification of this vulnerability is CVE-2026-25565. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in WeKan up to 8.18. This affects an unknown function of the file models/checklists.js of the component Checklist Handler. Performing a manipulation results in authorization bypass.
This vulnerability was named CVE-2026-25564. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in WeKan up to 8.18. The impacted element is an unknown function of the file models/checklists.js. Such manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-25563. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in WeKan up to 8.18. It has been rated as critical. The affected element is an unknown function of the file server/routes/attachmentApi.js of the component Attachment Upload API. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-25561. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in WeKan up to 8.18. It has been declared as critical. Impacted is an unknown function of the file packages/wekan-ldap/server/ldap.js. The manipulation results in ldap injection.
This vulnerability is known as CVE-2026-25560. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in WeKan up to 8.18. It has been classified as critical. This issue affects some unknown processing of the file models/boards.js. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-25568. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in WeKan up to 8.19 and classified as problematic. This vulnerability affects unknown code of the component Migration Operation Handler. Executing a manipulation can lead to incorrect authorization.
This vulnerability appears as CVE-2026-25859. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.