← Back

CVE-2025-65782

nvd nist
Published: Dec 15, 2025Modified: Dec 23, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in vote.positive / vote.negative arrays, enabling vote forgery and unauthorized voting.

Affected (1)

Products: Wekan Project: Wekan
1 product
Wekan
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.15

Timeline

No history available yet.