PT-2026-78653 · Wekan · Wekan
CVE-2026-68900
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wekan versions 8.72 through 10.22
Description
The
addBoardHTMLToZip() function in client/lib/exportHTML.js reads card titles and bodies using textContent, which decodes entity-encoded markup. These values, titleText and allText, are then interpolated into content.innerHTML within the exported index.html file. A board member can store an entity-encoded event-handler payload in a card title that remains inactive on the live board but is executed when a recipient opens the downloaded HTML export. This allows the script to read and transmit all board data contained in the export, including information added after the attacker's membership was revoked.Recommendations
Update to version 10.23.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wekan