5.7

CVE-2026-33473

Exploit

Vikunja has TOTP Reuse During Validity Window

Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patches the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VikunjaVikunja Version >= 0.13 < 2.2.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.169
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://vikunja.io/changelog/vikunja-v2.2.0-was-released
Release Notes
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-p747-qc5p-773r
Vendor Advisory
Exploit
https://vikunja.io/changelog/vikunja-v2.2.2-was-released
Release Notes