Metrics
Affected Vendors & Products
Tue, 10 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wekan Project
Wekan Project wekan |
|
| Vendors & Products |
Wekan Project
Wekan Project wekan |
Sat, 07 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier. | |
| Title | WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-10T16:09:27.734Z
Reserved: 2026-02-02T20:12:33.397Z
Link: CVE-2026-25567
Updated: 2026-02-10T16:09:15.261Z
Status : Analyzed
Published: 2026-02-07T22:16:02.333
Modified: 2026-02-10T21:56:33.353
Link: CVE-2026-25567
No data.