CVE-2026-33677
- EPSS 0.3%
- Veröffentlicht 24.03.2026 15:36:51
- Zuletzt bearbeitet 27.03.2026 16:29:43
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user...
CVE-2026-33676
- EPSS 0.33%
- Veröffentlicht 24.03.2026 15:35:37
- Zuletzt bearbeitet 27.03.2026 16:12:26
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related_tasks` field with full task objects for all related tasks without checking whether the requesting us...
CVE-2026-33675
- EPSS 0.27%
- Veröffentlicht 24.03.2026 15:33:05
- Zuletzt bearbeitet 27.03.2026 16:20:07
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `DownloadFile` and `DownloadFileWithHeaders` in `pkg/modules/migration/helpers.go` make arbitrary HTTP GET requests without any SSR...
CVE-2026-33668
- EPSS 0.45%
- Veröffentlicht 24.03.2026 15:30:27
- Zuletzt bearbeitet 27.03.2026 16:44:58
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three ...
CVE-2026-33474
- EPSS 0.32%
- Veröffentlicht 24.03.2026 15:21:19
- Zuletzt bearbeitet 27.03.2026 16:47:45
Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0, unbounded image decoding and resizing during preview generation lets an attacker exhaust CPU and memory with highly compressed b...
CVE-2026-33473
- EPSS 0.26%
- Veröffentlicht 24.03.2026 15:18:14
- Zuletzt bearbeitet 27.03.2026 16:53:32
Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patches the iss...
CVE-2026-33336
- EPSS 1.12%
- Veröffentlicht 24.03.2026 15:16:14
- Zuletzt bearbeitet 27.03.2026 16:54:35
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigati...
- EPSS 0.25%
- Veröffentlicht 24.03.2026 15:07:41
- Zuletzt bearbeitet 27.03.2026 16:58:07
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validati...
CVE-2026-33334
- EPSS 0.39%
- Veröffentlicht 24.03.2026 15:02:20
- Zuletzt bearbeitet 27.03.2026 16:21:09
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. Thi...
CVE-2026-33316
- EPSS 0.36%
- Veröffentlicht 24.03.2026 14:59:17
- Zuletzt bearbeitet 24.03.2026 19:22:10
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their accounts. The `ResetPassword()` function sets the user’s status to `Statu...