Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53447

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.

EPSS

Процентиль: 14%
0.00231
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
debian
24 дня назад

Wekan is open source kanban built with Meteor. Prior to 9.35, the Weka ...

EPSS

Процентиль: 14%
0.00231
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639