Where
-Infinity
0

Vikunja VikunjaVikunja 0.24.0 Broken Object Level Authorization via Link-Share Token

Risk 84
Severity
9.3
First published (updated )

Vikunja VikunjaVikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

Risk 86
Severity
9.3
First published (updated )

go/code.vikunja.io/apiVikunja's Scoped API tokens with projects.background permission can delete project backgrounds

Risk 34
Severity
5.4
First published (updated )

go/code.vikunja.io/apiVikunja has a File Size Limit Bypass via Vikunja Import

Risk 48
Severity
7.1
First published (updated )

go/code.vikunja.io/apiVikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output

Risk 21
Severity
4.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/code.vikunja.io/apiVikunja has HTML Injection via Task Titles in Overdue Email Notifications

Risk 34
Severity
5.4
First published (updated )

go/code.vikunja.io/apiVikunja has an Algorithmic Complexity DoS in Repeating Task Handler

Risk 38
Severity
6.5
First published (updated )

go/code.vikunja.io/apiVikunja has Missing Authorization on CalDAV Task Read

Risk 22
Severity
4.3
First published (updated )

go/code.vikunja.io/apiVikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout

Risk 43
Severity
7.5
First published (updated )

go/code.vikunja.io/apiVikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/code.vikunja.io/apiVikunja Affected by Privilege Escalation via Project Reparenting

Risk 69
Severity
8.3
First published (updated )

go/code.vikunja.io/apiVikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

Risk 40
Severity
6.5
First published (updated )

go/code.vikunja.io/apiVikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path

Risk 66
Severity
9.1
First published (updated )

Vikunja VikunjaVikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion

Risk 27
Severity
6.9
EPSS
0.04%
First published (updated )

Vikunja VikunjaVikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation

Risk 31
Severity
7.5
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Vikunja VikunjaVikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections

Risk 37
Severity
7.4
EPSS
0.03%
First published (updated )

Vikunja VikunjaVikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion

Risk 43
Severity
8.1
EPSS
0.03%
First published (updated )

Vikunja VikunjaWebhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API

Risk 27
Severity
6.5
EPSS
0.03%
First published (updated )

Vikunja VikunjaVikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read

Risk 27
Severity
6.5
EPSS
0.03%
First published (updated )

Vikunja VikunjaVikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources

Risk 28
Severity
6.4
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Vikunja VikunjaVikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect

Risk 43
Severity
7.1
EPSS
0.13%
First published (updated )

Vikunja Vikunja DesktopVikunja Desktop vulnerable to Remote Code Execution via same-window navigation

Risk 56
Severity
6.5
EPSS
0.38%
First published (updated )

Vikunja Vikunja DesktopVikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal

Risk 52
Severity
6.4
EPSS
0.04%
First published (updated )

Vikunja Vikunja DesktopVikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegration

Risk 58
Severity
6.5
EPSS
0.44%
First published (updated )

go/code.vikunja.io/apiVikunja Affected by DoS via Image Preview Generation

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/code.vikunja.io/apiVikunja has TOTP Reuse During Validity Window

Risk 24
Severity
5.7
EPSS
0.03%
First published (updated )

go/code.vikunja.io/apiVikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement

Risk 43
Severity
8.1
EPSS
0.03%
First published (updated )

go/code.vikunja.io/apiVikunja has a 2FA Bypass via Caldav Basic Auth

Risk 23
Severity
6.9
EPSS
0.08%
First published (updated )

go/code.vikunja.io/apiVikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )

Vikunja VikunjaRead-only Vikunja users can delete project background images via broken object-level authorization

Risk 25
Severity
5.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203