All 35 CVE vulnerabilities found in vikunja, with AI-generated Chinese analysis, references, and POCs.
Vendor: go-vikunja
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-27819 | Vikunja has Path Traversal in CLI Restore CWE-22 | 7.2 | High | 2026-02-25 |
| CVE-2026-27616 | Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token Exposure CWE-79 | 7.3 | High | 2026-02-25 |
| CVE-2026-27575 | Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change CWE-521 | 9.1 | Critical | 2026-02-25 |
| CVE-2026-27116 | Vikunja has Reflected HTML Injection via filter Parameter in Projects Module CWE-79 | 6.1 | Medium | 2026-02-25 |
| CVE-2026-25935 | Vikunja Affected by XSS Via Task Preview CWE-80 | 5.4AI | MediumAI | 2026-02-11 |
All 35 known CVE vulnerabilities affecting vikunja with full Chinese analysis, references, and POCs where available.