| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| wekan-8.16-amd64-windows.zip | 2025-11-02 | 95.1 MB | |
| wekan-8.16-amd64.zip | 2025-11-02 | 97.7 MB | |
| README.md | 2025-11-02 | 1.9 kB | |
| v8.16 source code.tar.gz | 2025-11-02 | 26.2 MB | |
| v8.16 source code.zip | 2025-11-02 | 26.8 MB | |
| Totals: 5 Items | 245.9 MB | 1 | |
This release fixes SpaceBleed that is the following CRITICAL SECURITY ISSUES:
- Fix SECURITY ISSUE 1: File Attachments enables stored XSS (High). Thanks to Siam Thanat Hack (STH) and xet7.
- Fix SECURITY ISSUE 2: Access to boards of any Orgs/Teams, and avatar permissions. Thanks to Siam Thanat Hack (STH) and xet7.
- Fix SECURITY ISSUE 3: Unauthenticated (or any) user can update board sort. Thanks to Siam Thanat Hack (STH) and xet7.
- Fix SECURITY ISSUE 4: Members can forge others’ votes (Low). Bonus: Similar fixes to planning poker too done by xet7. Thanks to Siam Thanat Hack (STH) and xet7.
- Fix SECURITY ISSUE 5: Attachment API uses bearer value as userId and DoS (Low). Thanks to Siam Thanat Hack (STH) and xet7.
and adds the following new features:
- List menu / More / Delete duplicate lists that do not have any cards. Thanks to xet7.
- Disabled migrations that happen when opening board. Defaulting to per-swimlane lists and drag drop list to same or different swimlane. Thanks to xet7.
and fixes the following bugs:
- Fix changing swimlane color to not reload webpage. Thanks to xet7.
Thanks to above GitHub users for their contributions and translators for their translations.