Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vikunja — Vulnerabilities & Security Advisories 39

All 39 CVE vulnerabilities found in vikunja, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Vikunja open-source task management application, categorized by Common Weakness Enumerations and specific vendor advisories. It collects disclosed issues ranging from remote code execution and cross-site scripting to authentication bypasses and information disclosure flaws, covering vulnerability reports published from early 2023 through the present day. Here, users can systematically track Vikunja’s security advisories to understand how the vendor addresses critical defects, analyze trends within specific weakness classes to assess overall product resilience, and review the complete vulnerability history to evaluate the impact on their self-hosted instances. The data includes CVSS scores, affected versions, patch release dates, and workarounds where immediate fixes were unavailable, providing a comprehensive view of the software's security posture over time. This resource is designed for system administrators, security researchers, and DevOps engineers who require detailed, factual information to maintain secure deployments and prioritize remediation efforts. By centralizing this information, the page facilitates informed decision-making regarding upgrade paths and configuration hardening, ensuring that stakeholders have access to accurate, timely data necessary for protecting their environments against known exploits.

Vendor: go-vikunja

CVE ID Title CVSS Severity Published
CVE-2026-76216 Vikunja through 2.4.0 Principal-Type Confusion via LinkSharing CWE-639 7.5 High 2026-08-19
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token CWE-639 6.5 Medium 2026-08-02
CVE-2026-68581 Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision CWE-863 8.1 High 2026-08-02
CVE-2026-56765 Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR CWE-639 9.8 Critical 2026-07-10
CVE-2026-40103 Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds CWE-836 4.3 Medium 2026-04-10
CVE-2026-35602 Vikunja has a File Size Limit Bypass via Vikunja Import CWE-770 5.4 Medium 2026-04-10
CVE-2026-35601 Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output CWE-93 4.1 Medium 2026-04-10
CVE-2026-35600 Vikunja has HTML Injection via Task Titles in Overdue Email Notifications CWE-79 5.4 Medium 2026-04-10
CVE-2026-35599 Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler CWE-407 6.5 Medium 2026-04-10
CVE-2026-35598 Vikunja has Missing Authorization on CalDAV Task Read CWE-862 4.3 Medium 2026-04-10
CVE-2026-35597 Vikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout CWE-307 5.9 Medium 2026-04-10
CVE-2026-35596 Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug CWE-863 4.3 Medium 2026-04-10
CVE-2026-35595 Vikunja Affected by Privilege Escalation via Project Reparenting CWE-269 8.3 High 2026-04-10
CVE-2026-35594 Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade CWE-613 6.5 Medium 2026-04-10
CVE-2026-34727 Vikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path CWE-287 7.4 High 2026-04-10
CVE-2026-33700 Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion CWE-639 2.7 - 2026-03-24
CVE-2026-33680 Vikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation CWE-285 7.5 High 2026-03-24
CVE-2026-33679 Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections CWE-918 6.4 Medium 2026-03-24
CVE-2026-33678 Vikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion CWE-639 8.1 High 2026-03-24
CVE-2026-33677 Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API CWE-200 6.5 Medium 2026-03-24
CVE-2026-33676 Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read CWE-863 6.5 Medium 2026-03-24
CVE-2026-33675 Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources CWE-918 6.4 Medium 2026-03-24
CVE-2026-33668 Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect CWE-285 4.4 - 2026-03-24
CVE-2026-33474 Vikunja Affected by DoS via Image Preview Generation CWE-400 6.5 Medium 2026-03-24
CVE-2026-33473 Vikunja has TOTP Reuse During Validity Window CWE-287 5.7 Medium 2026-03-24
CVE-2026-33336 Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation CWE-94 9.6 - 2026-03-24
CVE-2026-33335 Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal CWE-939 6.1 - 2026-03-24
CVE-2026-33334 Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegration CWE-94 9.0 - 2026-03-24
CVE-2026-33316 Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement CWE-284 8.1 High 2026-03-24
CVE-2026-33315 Vikunja has a 2FA Bypass via Caldav Basic Auth CWE-288 5.3 - 2026-03-24

All 39 known CVE vulnerabilities affecting vikunja with full Chinese analysis, references, and POCs where available.