Vikunja是Vikunja开源的一个待办事项应用程序。 Vikunja 2.0.0之前版本存在安全漏洞,该漏洞源于Projects模块中filter参数未进行输出编码,可能导致反射型HTML注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-vikunja | vikunja | < 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27575 | 9.1 CRITICAL | Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change |
| CVE-2026-27616 | 7.3 HIGH | Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upl |
| CVE-2026-27819 | 7.2 HIGH | Vikunja has Path Traversal in CLI Restore |
No comments yet