PT-2026-78653 · Wekan · Wekan

CVE-2026-68900

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wekan versions 8.72 through 10.22
Description The addBoardHTMLToZip() function in client/lib/exportHTML.js reads card titles and bodies using textContent, which decodes entity-encoded markup. These values, titleText and allText, are then interpolated into content.innerHTML within the exported index.html file. A board member can store an entity-encoded event-handler payload in a card title that remains inactive on the live board but is executed when a recipient opens the downloaded HTML export. This allows the script to read and transmit all board data contained in the export, including information added after the attacker's membership was revoked.
Recommendations Update to version 10.23.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68900
GHSA-8R5P-4Q9J-F5JX

Affected Products

Wekan