Launch Week Day 1: Announcing Security Design Review
go

code.vikunja.io/api

View on go registry
57 Total advisories
57 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 4.1
Go

CVE-2026-35601

Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output

HIGH 8.3
Go

CVE-2026-35595

Vikunja vulnerable to Privilege Escalation via Project Reparenting

UNKNOWN
Go

CVE-2026-35601

Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-35595

Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api

MEDIUM 5.4
Go

CVE-2026-40103

Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds

MEDIUM 5.4
Go

CVE-2026-35600

Vikunja has HTML Injection via Task Titles in Overdue Email Notifications

MEDIUM 5.4
Go

CVE-2026-35602

Vikunja has File Size Limit Bypass via Vikunja Import

HIGH 7.4
Go

CVE-2026-34727

Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path

MEDIUM 6.5
Go

CVE-2026-35594

Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

MEDIUM 6.5
Go

CVE-2026-35599

Vikunja has Algorithmic Complexity DoS in Repeating Task Handler

MEDIUM 4.3
Go

CVE-2026-35598

Vikunja Missing Authorization on CalDAV Task Read

MEDIUM 5.9
Go

CVE-2026-35597

Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout

MEDIUM 4.3
Go

CVE-2026-35596

Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug

MEDIUM 6.4
Go

CVE-2026-33679

Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download

HIGH 7.5
Go

CVE-2026-33680

Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation

CRITICAL 9.1
Go

GO-2026-4855

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

UNKNOWN
Go

CVE-2026-33668

Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect

UNKNOWN
Go

CVE-2026-33700

Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion

MEDIUM 6.5
Go

CVE-2026-33676

Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read

MEDIUM 6.4
Go

CVE-2026-33675

Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources

HIGH 8.1
Go

CVE-2026-33678

Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion

MEDIUM 6.5
Go

CVE-2026-33677

Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API

UNKNOWN
Go

CVE-2026-33675

Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33700

Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33677

Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33680

Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33679

Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api

UNKNOWN
Go

GHSA-2pv8-4c52-mf8j

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33668

Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33678

Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33676

Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api

MEDIUM 6.5
Go

CVE-2026-33474

Vikunja Affected by DoS via Image Preview Generation

HIGH 8.1
Go

CVE-2026-33316

Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement

UNKNOWN
Go

CVE-2026-33315

Vikunja has a 2FA Bypass via Caldav Basic Auth

UNKNOWN
Go

CVE-2026-33313

Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments

MEDIUM 5.7
Go

CVE-2026-33473

Vikunja has TOTP Reuse During Validity Window

UNKNOWN
Go

CVE-2026-33312

Vikunja read-only users can delete project background images via broken object-level authorization

MEDIUM 5.3
Go

CVE-2026-29794

Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers

UNKNOWN
Go

CVE-2026-33473

Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33474

Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-29794

Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33315

Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33313

Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33316

Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-33312

Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api

CRITICAL 9.8
Go

CVE-2026-28268

Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

UNKNOWN
Go

CVE-2026-28268

Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-27575

Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api

CRITICAL 9.1
Go

CVE-2026-27575

Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change

UNKNOWN
Go

CVE-2026-27819

Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api

HIGH 7.2
Go

CVE-2026-27819

Vikunja has Path Traversal in CLI Restore

UNKNOWN
Go

CVE-2026-27116

Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api

MEDIUM 6.1
Go

CVE-2026-27116

Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module

UNKNOWN
Go

CVE-2026-27616

Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api

HIGH 7.3
Go

CVE-2026-27616

Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure

UNKNOWN
Go

CVE-2026-25935

Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api

UNKNOWN
Go

CVE-2026-25935

Vikunja Vulnerable to XSS Via Task Preview

Ready to move

Start Securing

Free, no credit card | First findings in minutes