Vulnerabilities
CVE-2026-35601
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output
CVE-2026-35595
Vikunja vulnerable to Privilege Escalation via Project Reparenting
CVE-2026-35601
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api
CVE-2026-35595
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api
CVE-2026-40103
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds
CVE-2026-35600
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
CVE-2026-35602
Vikunja has File Size Limit Bypass via Vikunja Import
CVE-2026-34727
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE-2026-35594
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE-2026-35599
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler
CVE-2026-35598
Vikunja Missing Authorization on CalDAV Task Read
CVE-2026-35597
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
CVE-2026-35596
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVE-2026-33679
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download
CVE-2026-33680
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation
GO-2026-4855
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
CVE-2026-33668
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVE-2026-33700
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion
CVE-2026-33676
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read
CVE-2026-33675
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources
CVE-2026-33678
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion
CVE-2026-33677
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API
CVE-2026-33675
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api
CVE-2026-33700
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api
CVE-2026-33677
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api
CVE-2026-33680
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api
CVE-2026-33679
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api
GHSA-2pv8-4c52-mf8j
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api
CVE-2026-33668
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api
CVE-2026-33678
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api
CVE-2026-33676
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api
CVE-2026-33474
Vikunja Affected by DoS via Image Preview Generation
CVE-2026-33316
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVE-2026-33315
Vikunja has a 2FA Bypass via Caldav Basic Auth
CVE-2026-33313
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments
CVE-2026-33473
Vikunja has TOTP Reuse During Validity Window
CVE-2026-33312
Vikunja read-only users can delete project background images via broken object-level authorization
CVE-2026-29794
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
CVE-2026-33473
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api
CVE-2026-33474
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api
CVE-2026-29794
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api
CVE-2026-33315
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api
CVE-2026-33313
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api
CVE-2026-33316
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api
CVE-2026-33312
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api
CVE-2026-28268
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
CVE-2026-28268
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api
CVE-2026-27575
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api
CVE-2026-27575
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
CVE-2026-27819
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api
CVE-2026-27819
Vikunja has Path Traversal in CLI Restore
CVE-2026-27116
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api
CVE-2026-27116
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module
CVE-2026-27616
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api
CVE-2026-27616
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure
CVE-2026-25935
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api
CVE-2026-25935
Vikunja Vulnerable to XSS Via Task Preview
Ready to move
Start Securing
Free, no credit card | First findings in minutes