Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-1963

Опубликовано: 05 фев. 2026
Источник: nvd
CVSS3: 6.3
CVSS3: 9.8
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates this issue. The patch is identified as c413a7e860bc4d93fe2adcf82516228570bf382d. Upgrading the affected component is advised.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*
Версия до 8.21 (исключая)

EPSS

Процентиль: 7%
0.00025
Низкий

6.3 Medium

CVSS3

9.8 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.3
debian
около 2 месяцев назад

A vulnerability was found in WeKan up to 8.20. This affects an unknown ...

CVSS3: 6.3
github
около 2 месяцев назад

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates this issue. The patch is identified as c413a7e860bc4d93fe2adcf82516228570bf382d. Upgrading the affected component is advised.

EPSS

Процентиль: 7%
0.00025
Низкий

6.3 Medium

CVSS3

9.8 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-266