Vikunja是Vikunja开源的一个待办事项应用程序。 Vikunja 2.0.0之前版本存在代码问题漏洞,该漏洞源于允许设置弱密码且用户更改密码后活动会话仍然有效,可能导致账户劫持和持久访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-vikunja | vikunja | < 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27616 | 7.3 HIGH | Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upl |
| CVE-2026-27819 | 7.2 HIGH | Vikunja has Path Traversal in CLI Restore |
| CVE-2026-27116 | 6.1 MEDIUM | Vikunja has Reflected HTML Injection via filter Parameter in Projects Module |
No comments yet