CVE-2026-34727
- EPSS 0.28%
- Veröffentlicht 10.04.2026 15:45:30
- Zuletzt bearbeitet 20.04.2026 19:55:52
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enroll...
CVE-2026-33700
- EPSS 0.21%
- Veröffentlicht 24.03.2026 15:51:40
- Zuletzt bearbeitet 30.03.2026 13:35:39
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:project/shares/:share` endpoint does not verify that the link share belongs to the project specified in the URL. An attacker with ad...
CVE-2026-33680
- EPSS 0.4%
- Veröffentlicht 24.03.2026 15:47:47
- Zuletzt bearbeitet 30.03.2026 13:42:38
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method allows link share authenticated users to list all link shares for a project, including their secret hashes. While `LinkSharing....
CVE-2026-33679
- EPSS 0.33%
- Veröffentlicht 24.03.2026 15:46:10
- Zuletzt bearbeitet 30.03.2026 13:56:01
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Conn...
CVE-2026-33678
- EPSS 0.27%
- Veröffentlicht 24.03.2026 15:44:06
- Zuletzt bearbeitet 30.03.2026 13:57:13
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the task ID from the URL path. The permission check in `CanRead()` validates ...
CVE-2026-33677
- EPSS 0.3%
- Veröffentlicht 24.03.2026 15:36:51
- Zuletzt bearbeitet 27.03.2026 16:29:43
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user...
CVE-2026-33676
- EPSS 0.33%
- Veröffentlicht 24.03.2026 15:35:37
- Zuletzt bearbeitet 27.03.2026 16:12:26
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related_tasks` field with full task objects for all related tasks without checking whether the requesting us...
CVE-2026-33675
- EPSS 0.27%
- Veröffentlicht 24.03.2026 15:33:05
- Zuletzt bearbeitet 27.03.2026 16:20:07
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `DownloadFile` and `DownloadFileWithHeaders` in `pkg/modules/migration/helpers.go` make arbitrary HTTP GET requests without any SSR...
CVE-2026-33668
- EPSS 0.45%
- Veröffentlicht 24.03.2026 15:30:27
- Zuletzt bearbeitet 27.03.2026 16:44:58
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three ...
CVE-2026-33474
- EPSS 0.32%
- Veröffentlicht 24.03.2026 15:21:19
- Zuletzt bearbeitet 27.03.2026 16:47:45
Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0, unbounded image decoding and resizing during preview generation lets an attacker exhaust CPU and memory with highly compressed b...