code.vikunja.io/api
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~31 days
- Last 12 months
- 0
Details
- First release
- Aug 03, 2022
| Version | Released | |
|---|---|---|
v0.24.6
patch
38 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55065
GO-2026-6313
GHSA-gg93-x632-9ccv
Sep 02, 2026
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.6
patch
Dependencies (65)
+ 57 more |
|
v0.24.5
patch
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.5
patch
Dependencies (65)
+ 57 more |
|
v0.24.4
patch
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.4
patch
Dependencies (65)
+ 57 more |
|
v0.24.3
patch
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.3
patch
Dependencies (65)
+ 57 more |
|
v0.24.2
patch
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.2
patch
Dependencies (66)
+ 58 more |
|
v0.24.1
patch
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.1
patch
Dependencies (66)
+ 58 more |
|
v0.24.0
minor
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.24.0
minor
Dependencies (65)
+ 57 more |
|
v0.23.0
minor
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.23.0
minor
Dependencies (62)
+ 54 more |
|
v0.22.1
patch
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.22.1
patch
Dependencies (62)
+ 54 more |
|
v0.22.0
minor
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.22.0
minor
Dependencies (61)
+ 53 more |
|
v0.21.0
minor
37 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54766
GO-2026-6311
GHSA-f27p-pw2p-9pr4
Sep 02, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.21.0
minor
Dependencies (59)
+ 51 more |
|
v0.20.4
patch
36 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.20.4
patch
Dependencies (59)
+ 51 more |
|
v0.20.5
patch
36 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.20.5
patch
|
|
v0.20.3
patch
36 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.20.3
patch
Dependencies (59)
+ 51 more |
|
v0.20.2
patch
36 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33312
GO-2026-4795
GHSA-564f-wx8x-878h
Mar 23, 2026
Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.20.2
patch
Dependencies (59)
+ 51 more |
|
v0.20.1
patch
35 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.20.1
patch
Dependencies (57)
+ 49 more |
|
v0.20.0
minor
35 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.20.0
minor
Dependencies (57)
+ 49 more |
|
v0.19.2
patch
35 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.19.2
patch
Dependencies (58)
+ 50 more |
|
v0.19.1
patch
35 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.19.1
patch
Dependencies (58)
+ 50 more |
|
v0.19.0
initial
35 CVEs
CVE-2026-55067
GO-2026-6307
GHSA-569v-q83c-3j3g
Sep 02, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55064
GO-2026-6306
GHSA-44v6-7fxq-vgf4
Sep 02, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v2.3.0 before v2.4.0. Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55066
GO-2026-6308
GHSA-5pg6-m483-7vrg
Sep 02, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.4.0. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-40103
GO-2026-5650
GHSA-v479-vf79-mg83
Jun 25, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35599
GO-2026-5608
GHSA-r4fg-73rc-hhh7
Jun 25, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api Vikunja has Algorithmic Complexity DoS in Repeating Task Handler in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35602
GO-2026-5582
GHSA-qh78-rvg3-cv54
Jun 25, 2026
Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api Vikunja has File Size Limit Bypass via Vikunja Import in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35596
GO-2026-5428
GHSA-hj5c-mhh2-g7jq
Jun 25, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35597
GO-2026-5362
GHSA-fgfv-pv97-6cmj
Jun 25, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34727
GO-2026-5258
GHSA-8jvc-mcx6-r4cg
Jun 25, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35594
GO-2026-5276
GHSA-96q5-xm3p-7m84
Jun 25, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35598
GO-2026-5114
GHSA-48ch-p4gq-x46x
Jun 25, 2026
Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api Vikunja Missing Authorization on CalDAV Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35600
GO-2026-5111
GHSA-45q4-x4r9-8fqj
Jun 25, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api Vikunja has HTML Injection via Task Titles in Overdue Email Notifications in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35595
GO-2026-4952
GHSA-2vq4-854f-5c72
May 20, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api Vikunja vulnerable to Privilege Escalation via Project Reparenting in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-35601
GO-2026-4951
GHSA-2g7h-7rqr-9p4r
May 20, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.3.0. References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-33679
GO-2026-4852
GHSA-g9xj-752q-xh63
Mar 26, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-56765
GO-2026-4855
GHSA-2pv8-4c52-mf8j
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Jul 11, 2026 · Source: OSV.dev
CVE-2026-33675
GO-2026-4851
GHSA-g66v-54v9-52pr
Mar 26, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33678
GO-2026-4853
GHSA-jfmm-mjcp-8wq2
Mar 26, 2026
Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33700
GO-2026-4850
GHSA-f95f-77jx-fcjc
Mar 26, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33668
GO-2026-4849
GHSA-94xm-jj8x-3cr4
Mar 26, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33677
GO-2026-4846
GHSA-7c2g-p23p-4jg3
Mar 26, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33676
GO-2026-4847
GHSA-8cmm-j6c4-rr8v
Mar 26, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1. References
Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33680
GO-2026-4848
GHSA-8hp8-9fhr-pfm9
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.2. References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-33474
GO-2026-4811
GHSA-wc83-79hj-hpmq
Mar 23, 2026
Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0. Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33473
GO-2026-4805
GHSA-p747-qc5p-773r
Mar 23, 2026
Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29794
GO-2026-4791
GHSA-m547-hp4w-j6jx
Mar 23, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33315
GO-2026-4794
GHSA-47cr-f226-r4pq
Mar 23, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33316
GO-2026-4798
GHSA-vq4q-79hh-q767
Mar 23, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33313
GO-2026-4797
GHSA-mr3j-p26x-72x4
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28268
GO-2026-4575
GHSA-rfjg-6m84-crj2
Mar 10, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse in code.vikunja.io/api References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-27819
GO-2026-4556
GHSA-42wg-38gx-85rh
Feb 27, 2026
Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api Vikunja has Path Traversal in CLI Restore in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27575
GO-2026-4551
GHSA-3ccg-x393-96v8
Feb 27, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27616
GO-2026-4553
GHSA-7jp5-298q-jg98
Feb 27, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-27116
GO-2026-4552
GHSA-4qgr-4h56-8895
Feb 27, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module in code.vikunja.io/api References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-25935
GO-2026-4480
GHSA-m4g2-2q66-vc9v
Feb 17, 2026
Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api Vikunja Vulnerable to XSS Via Task Preview in code.vikunja.io/api References
Updated Feb 19, 2026 · Source: OSV.dev |
v0.19.0
initial
Dependencies (58)
+ 50 more |