Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vikunja — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in vikunja, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common vulnerability data for the open-source project Vikunja, categorized by vulnerability type and relevant security tags. It collects reported security issues affecting the Vikunja task management application, covering historical records from its early releases through recent versions. Here, you can track vendor advisories to stay informed about published patches, understand the prevalence and characteristics of specific weakness classes within this codebase, and look up a product's vulnerability history to assess long-term security posture. Vikunja is a self-hosted to-do application that allows users to organize their tasks and projects efficiently. Like many web applications, it has been subject to various security assessments over time. The aggregated data aims to provide a clear view of how the project has addressed security flaws, including issues related to authentication, access control, and data integrity. By reviewing these entries, developers and administrators can gain insights into potential risks and evaluate the effectiveness of mitigation strategies. The information presented here is derived from public databases and vendor notifications, ensuring a comprehensive overview without duplicating individual CVE details. This resource serves as a centralized reference for understanding the security evolution of Vikunja, helping stakeholders make informed decisions about deployment and maintenance. It does not include speculative or unverified claims, focusing strictly on documented incidents. Users interested in the technical specifics of each flaw can cross-reference the provided summaries with official advisories for deeper analysis.

Vendor: go-vikunja

CVE IDTitleCVSSSeverityPublished
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token CWE-639 6.5 Medium2026-08-02
CVE-2026-68581 Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision CWE-863 8.1 High2026-08-02
CVE-2026-56765 Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR CWE-639 9.8 Critical2026-07-10
CVE-2026-40103 Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds CWE-836 4.3 Medium2026-04-10
CVE-2026-35602 Vikunja has a File Size Limit Bypass via Vikunja Import CWE-770 5.4 Medium2026-04-10
CVE-2026-35601 Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output CWE-93 4.1 Medium2026-04-10
CVE-2026-35600 Vikunja has HTML Injection via Task Titles in Overdue Email Notifications CWE-79 5.4 Medium2026-04-10
CVE-2026-35599 Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler CWE-407 6.5 Medium2026-04-10
CVE-2026-35598 Vikunja has Missing Authorization on CalDAV Task Read CWE-862 4.3 Medium2026-04-10
CVE-2026-35597 Vikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout CWE-307 5.9 Medium2026-04-10
CVE-2026-35596 Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug CWE-863 4.3 Medium2026-04-10
CVE-2026-35595 Vikunja Affected by Privilege Escalation via Project Reparenting CWE-269 8.3 High2026-04-10
CVE-2026-35594 Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade CWE-613 6.5 Medium2026-04-10
CVE-2026-34727 Vikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path CWE-287 7.4 High2026-04-10
CVE-2026-33700 Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion CWE-639 2.7 -2026-03-24
CVE-2026-33680 Vikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation CWE-285 7.5 High2026-03-24
CVE-2026-33679 Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections CWE-918 6.4 Medium2026-03-24
CVE-2026-33678 Vikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion CWE-639 8.1 High2026-03-24
CVE-2026-33677 Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API CWE-200 6.5 Medium2026-03-24
CVE-2026-33676 Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read CWE-863 6.5 Medium2026-03-24
CVE-2026-33675 Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources CWE-918 6.4 Medium2026-03-24
CVE-2026-33668 Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect CWE-285 4.4 -2026-03-24
CVE-2026-33474 Vikunja Affected by DoS via Image Preview Generation CWE-400 6.5 Medium2026-03-24
CVE-2026-33473 Vikunja has TOTP Reuse During Validity Window CWE-287 5.7 Medium2026-03-24
CVE-2026-33336 Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation CWE-94 9.6 -2026-03-24
CVE-2026-33335 Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal CWE-939 6.1 -2026-03-24
CVE-2026-33334 Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegration CWE-94 9.0 -2026-03-24
CVE-2026-33316 Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement CWE-284 8.1 High2026-03-24
CVE-2026-33315 Vikunja has a 2FA Bypass via Caldav Basic Auth CWE-288 5.3 -2026-03-24
CVE-2026-33313 Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments CWE-639 4.3 -2026-03-24

All 38 known CVE vulnerabilities affecting vikunja with full Chinese analysis, references, and POCs where available.