Vikunja

Vikunja

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 24.03.2026 15:16:14
  • Zuletzt bearbeitet 27.03.2026 16:54:35

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigati...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 24.03.2026 15:07:41
  • Zuletzt bearbeitet 27.03.2026 16:58:07

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validati...

  • EPSS 0.14%
  • Veröffentlicht 24.03.2026 15:02:20
  • Zuletzt bearbeitet 27.03.2026 16:21:09

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. Thi...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 24.03.2026 14:59:17
  • Zuletzt bearbeitet 24.03.2026 19:22:10

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their accounts. The `ResetPassword()` function sets the user’s status to `Statu...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 24.03.2026 14:53:34
  • Zuletzt bearbeitet 24.03.2026 19:21:46

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login using Basic Authentication, which in turn allows users to bypass the TOTP on 2FA-enabled accounts. The user can then access stand...

  • EPSS 0.03%
  • Veröffentlicht 24.03.2026 14:50:11
  • Zuletzt bearbeitet 24.03.2026 19:21:12

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read any task comment by ID, regardless of whether they have access to the task the comment belongs to, by substituting the task ID in t...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.03.2026 14:42:14
  • Zuletzt bearbeitet 24.03.2026 21:17:38

Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, the `DELETE /api/v1/projects/:project/background` endpoint checks `CanRead` permission instead of `CanUpdate`, allowing any user wi...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 20.03.2026 14:39:59
  • Zuletzt bearbeitet 24.03.2026 21:18:04

Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unauthenticated users are able to bypass the application's built-in rate-limits by spoofing the `X-Forwarded-For` or `X-Real-IP` heade...

  • EPSS 0.04%
  • Veröffentlicht 27.02.2026 20:16:29
  • Zuletzt bearbeitet 06.03.2026 21:03:09

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a fa...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.02.2026 21:40:38
  • Zuletzt bearbeitet 05.03.2026 16:32:00

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vikunja/vikunja repository fails to sanitize file paths within the provided ZIP archiv...