Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

go-vikunja — Vulnerabilities & Security Advisories 59

Browse all 59 CVE security advisories affecting go-vikunja. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Vikunja is an open-source, self-hosted task management application designed for personal and team productivity, written in Go with a Vue.js frontend. Security audits have identified thirty-five Common Vulnerabilities and Exposures (CVEs) associated with the platform, primarily stemming from its web interface and API endpoints. Historically, these flaws frequently involve Cross-Site Scripting (XSS), SQL injection, and improper access control mechanisms that allow privilege escalation. Several incidents highlight risks related to unauthenticated remote code execution and insecure direct object references, which can expose sensitive user data or allow attackers to manipulate task records. The project’s architecture, while modern, has demonstrated vulnerabilities in input validation and session management. These recurring issues underscore the importance of rigorous code review and timely patching for administrators deploying Vikunja in production environments, as the cumulative risk profile suggests potential for significant data breaches if left unaddressed.

Found 59 results / 59 Clear Filters
Top products by go-vikunja: vikunja
CVE ID Title CVSS Severity Published
CVE-2026-35597 Vikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout — vikunja CWE-307 5.9 Medium 2026-04-10
CVE-2026-35596 Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug — vikunja CWE-863 4.3 Medium 2026-04-10
CVE-2026-35595 Vikunja Affected by Privilege Escalation via Project Reparenting — vikunja CWE-269 8.3 High 2026-04-10
CVE-2026-35594 Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade — vikunja CWE-613 6.5 Medium 2026-04-10
CVE-2026-34727 Vikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path — vikunja CWE-287 7.4 High 2026-04-10
CVE-2026-33700 Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion — vikunja CWE-639 2.7 - 2026-03-24
CVE-2026-33680 Vikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation — vikunja CWE-285 7.5 High 2026-03-24
CVE-2026-33679 Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections — vikunja CWE-918 6.4 Medium 2026-03-24
CVE-2026-33678 Vikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion — vikunja CWE-639 8.1 High 2026-03-24
CVE-2026-33677 Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API — vikunja CWE-200 6.5 Medium 2026-03-24
CVE-2026-33676 Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read — vikunja CWE-863 6.5 Medium 2026-03-24
CVE-2026-33675 Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources — vikunja CWE-918 6.4 Medium 2026-03-24
CVE-2026-33668 Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect — vikunja CWE-285 4.4 - 2026-03-24
CVE-2026-33474 Vikunja Affected by DoS via Image Preview Generation — vikunja CWE-400 6.5 Medium 2026-03-24
CVE-2026-33473 Vikunja has TOTP Reuse During Validity Window — vikunja CWE-287 5.7 Medium 2026-03-24
CVE-2026-33336 Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation — vikunja CWE-94 9.6 - 2026-03-24
CVE-2026-33335 Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal — vikunja CWE-939 6.1 - 2026-03-24
CVE-2026-33334 Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegration — vikunja CWE-94 9.0 - 2026-03-24
CVE-2026-33316 Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement — vikunja CWE-284 8.1 High 2026-03-24
CVE-2026-33315 Vikunja has a 2FA Bypass via Caldav Basic Auth — vikunja CWE-288 5.3 - 2026-03-24
CVE-2026-33313 Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments — vikunja CWE-639 4.3 - 2026-03-24
CVE-2026-33312 Read-only Vikunja users can delete project background images via broken object-level authorization — vikunja CWE-863 4.3 - 2026-03-20
CVE-2026-29794 Vikunja has Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers — vikunja CWE-807 5.3 Medium 2026-03-20
CVE-2026-28268 Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse — vikunja CWE-459 9.8 Critical 2026-02-27
CVE-2026-27819 Vikunja has Path Traversal in CLI Restore — vikunja CWE-22 7.2 High 2026-02-25
CVE-2026-27616 Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token Exposure — vikunja CWE-79 7.3 High 2026-02-25
CVE-2026-27575 Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change — vikunja CWE-521 9.1 Critical 2026-02-25
CVE-2026-27116 Vikunja has Reflected HTML Injection via filter Parameter in Projects Module — vikunja CWE-79 6.1 Medium 2026-02-25
CVE-2026-25935 Vikunja Affected by XSS Via Task Preview — vikunja CWE-80 5.4AI Medium AI 2026-02-11

This page lists every published CVE security advisory associated with go-vikunja. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.