go-vikunja vikunja
18 known vulnerabilities in go-vikunja vikunja, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-91985 CVSS 8.7 high Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only…
- CVE-2026-91984 CVSS 5.3 medium Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project…
- CVE-2026-91983 CVSS 5.3 medium Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query…
- CVE-2026-91982 CVSS 5.3 medium Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and…
- CVE-2026-91981 CVSS 5.3 medium Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only…
- CVE-2026-91980 CVSS 5.3 medium vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams…
- CVE-2026-91979 CVSS 7.1 high Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service…
- CVE-2026-91973 CVSS 8.7 high Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection…
- CVE-2026-91972 CVSS 8.7 high Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register…
- CVE-2026-91971 CVSS 7.1 high Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to…
- CVE-2026-91970 CVSS 7.1 high Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory…
- CVE-2026-91969 CVSS 7.1 high vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to…
- CVE-2026-91968 CVSS 7.1 high vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter…
- CVE-2026-55067 CVSS 5.0 medium Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST…
- CVE-2026-55066 CVSS 7.1 high Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST…
- CVE-2026-55065 CVSS 8.1 high Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view…
- CVE-2026-55064 CVSS 4.3 medium Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a…
- CVE-2026-54766 CVSS 5.3 medium Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in…