Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

vikunja — Vulnerabilities & Security Advisories 60

All 60 CVE vulnerabilities found in vikunja, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for the Vikunja product, focusing on security weaknesses identified in the open-source task management application. It collects publicly disclosed advisories, bug reports, and security patches related to Vikunja instances, covering a time range that extends from the product's initial public releases through recent updates. Readers can use this aggregation to track the vendor's security advisories, understand specific weakness classes such as cross-site scripting or access control issues, and look up the complete vulnerability history of the product to assess its long-term security posture. The collection includes both high-severity exploits and lower-impact defects, providing a comprehensive view of the product's security evolution without requiring a login or external navigation.

Vendor: go-vikunja

CVE ID Title CVSS Severity Published
CVE-2026-62376 Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read access CWE-312 8.1 High 2026-10-09
CVE-2026-62367 Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover CWE-287 7.5 High 2026-10-09
CVE-2026-57458 Vikunja: Scoped API token can mint unrestricted OAuth session credentials CWE-269 8.1 High 2026-10-09
CVE-2026-91985 Vikunja before 2.6.0 Privilege Escalation via Link Share Hash CWE-200 7.5 High 2026-09-15
CVE-2026-91984 Vikunja before 2.6.0 Broken Object-Level Authorization via task-position CWE-639 4.3 Medium 2026-09-15
CVE-2026-91983 Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter CWE-863 4.3 Medium 2026-09-15
CVE-2026-91982 Vikunja before 2.6.0 TOTP Secret Disclosure via API CWE-522 4.3 Medium 2026-09-15
CVE-2026-91981 Vikunja before 2.6.0 User Enumeration via v2 API CWE-200 4.3 Medium 2026-09-15
CVE-2026-91980 vikunja before 2.6.0 Team Enumeration via Project Share CWE-200 4.3 Medium 2026-09-15
CVE-2026-91979 Vikunja before 2.6.0 Denial of Service via Decompression Bomb CWE-400 6.5 Medium 2026-09-15
CVE-2026-91973 Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth CWE-307 7.5 High 2026-09-15
CVE-2026-91972 Vikunja before 2.6.0 Authentication Bypass via Unthrottled API CWE-307 7.5 High 2026-09-15
CVE-2026-91971 Vikunja before 2.6.0 Denial of Service via Avatar Upload CWE-400 6.5 Medium 2026-09-15
CVE-2026-91970 Vikunja before 2.6.0 Resource Exhaustion via Planka Migration CWE-770 6.5 Medium 2026-09-15
CVE-2026-91969 vikunja before 2.6.0 Resource Exhaustion via CSV Migration CWE-400 6.5 Medium 2026-09-15
CVE-2026-91968 vikunja before 2.6.0 Denial of Service via unbounded filter recursion CWE-674 6.5 Medium 2026-09-15
CVE-2026-55067 Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment CWE-639 5.0 Medium 2026-08-28
CVE-2026-55066 Vikunja: Cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id CWE-639 7.1 High 2026-08-28
CVE-2026-55065 Vikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api CWE-285 8.1 High 2026-08-28
CVE-2026-55064 Vikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 CWE-862 4.3 Medium 2026-08-28
CVE-2026-54766 Vikunja: Project duplication bypasses write-permission check on the target parent project CWE-285 5.3 Medium 2026-08-28
CVE-2026-76216 Vikunja through 2.4.0 Principal-Type Confusion via LinkSharing CWE-639 7.5 High 2026-08-19
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token CWE-639 6.5 Medium 2026-08-02
CVE-2026-68581 Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision CWE-863 8.1 High 2026-08-02
CVE-2026-56765 Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR CWE-639 9.8 Critical 2026-07-10
CVE-2026-40103 Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds CWE-836 4.3 Medium 2026-04-10
CVE-2026-35602 Vikunja has a File Size Limit Bypass via Vikunja Import CWE-770 5.4 Medium 2026-04-10
CVE-2026-35601 Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output CWE-93 4.1 Medium 2026-04-10
CVE-2026-35600 Vikunja has HTML Injection via Task Titles in Overdue Email Notifications CWE-79 5.4 Medium 2026-04-10
CVE-2026-35599 Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler CWE-407 6.5 Medium 2026-04-10

All 60 known CVE vulnerabilities affecting vikunja with full Chinese analysis, references, and POCs where available.