Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-vikunja | vikunja | < 2.2.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33316 | 8.1 HIGH | Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablem |
| CVE-2026-33678 | 8.1 HIGH | Vikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion |
| CVE-2026-33474 | 6.5 MEDIUM | Vikunja Affected by DoS via Image Preview Generation |
| CVE-2026-33677 | 6.5 MEDIUM | Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API |
| CVE-2026-33676 | 6.5 MEDIUM | Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorizatio |
| CVE-2026-33675 | 6.4 MEDIUM | Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Int |
| CVE-2026-33679 | 6.4 MEDIUM | Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections |
| CVE-2026-33473 | 5.7 MEDIUM | Vikunja has TOTP Reuse During Validity Window |
| CVE-2026-33315 | Vikunja has a 2FA Bypass via Caldav Basic Auth | |
| CVE-2026-33313 | Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments | |
| CVE-2026-33335 | Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openEx | |
| CVE-2026-33334 | Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegratio | |
| CVE-2026-33336 | Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation | |
| CVE-2026-33668 | Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and O | |
| CVE-2026-33700 | Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Projec |
No comments yet