Vikunja

Vikunja

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 10.04.2026 16:04:32
  • Zuletzt bearbeitet 17.04.2026 21:57:42

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task's project....

Exploit
  • EPSS 0.3%
  • Veröffentlicht 10.04.2026 16:03:19
  • Zuletzt bearbeitet 17.04.2026 21:59:18

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. When a TOTP validation fails, the login handler in pkg/routes/api/...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 10.04.2026 15:59:43
  • Zuletzt bearbeitet 17.04.2026 22:00:03

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a SQL operator precedence bug that allows any authenticated user to read any label that has at least one task association, regardle...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 10.04.2026 15:58:32
  • Zuletzt bearbeitet 17.04.2026 22:00:13

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new parent project when changing parent_project_id. However, Vikunja's perm...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 10.04.2026 15:55:04
  • Zuletzt bearbeitet 24.04.2026 14:53:24

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims without any server-si...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 10.04.2026 15:45:30
  • Zuletzt bearbeitet 20.04.2026 19:55:52

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enroll...

  • EPSS 0.21%
  • Veröffentlicht 24.03.2026 15:51:40
  • Zuletzt bearbeitet 30.03.2026 13:35:39

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:project/shares/:share` endpoint does not verify that the link share belongs to the project specified in the URL. An attacker with ad...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 24.03.2026 15:47:47
  • Zuletzt bearbeitet 30.03.2026 13:42:38

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method allows link share authenticated users to list all link shares for a project, including their secret hashes. While `LinkSharing....

Exploit
  • EPSS 0.4%
  • Veröffentlicht 24.03.2026 15:46:10
  • Zuletzt bearbeitet 30.03.2026 13:56:01

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Conn...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 24.03.2026 15:44:06
  • Zuletzt bearbeitet 30.03.2026 13:57:13

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the task ID from the URL path. The permission check in `CanRead()` validates ...