Vikunja
Vikunja: vulnerabilidades y CVE
Vikunja tiene 57 vulnerabilidades publicadas, 57 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses57
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-91985 | Alta (8.7) | 0.43% | — | 15 sept 2026 | Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the… |
| CVE-2026-91984 | Media (5.3) | 0.26% | — | 15 sept 2026 | Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant… |
| CVE-2026-91983 | Media (5.3) | 0.30% | — | 15 sept 2026 | Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter… |
| CVE-2026-91982 | Media (5.3) | 0.35% | — | 15 sept 2026 | Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a… |
| CVE-2026-91980 | Media (5.3) | 0.31% | — | 15 sept 2026 | vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams… |
| CVE-2026-91979 | Alta (7.1) | 0.44% | — | 15 sept 2026 | Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory… |
| CVE-2026-91973 | Alta (8.7) | 0.67% | — | 15 sept 2026 | Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests… |
| CVE-2026-91972 | Alta (8.7) | 0.63% | — | 15 sept 2026 | Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform… |
| CVE-2026-91970 | Alta (7.1) | 0.44% | — | 15 sept 2026 | Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration… |
| CVE-2026-91969 | Alta (7.1) | 0.44% | — | 15 sept 2026 | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV… |
| CVE-2026-91968 | Alta (7.1) | 0.44% | — | 15 sept 2026 | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply… |
| CVE-2026-91981 | Media (5.3) | 0.31% | — | 15 sept 2026 | Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm… |
| CVE-2026-91971 | Alta (7.1) | 0.44% | — | 15 sept 2026 | Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can… |
| CVE-2026-55067 | Media (5) | 0.34% | — | 28 ago 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by… |
| CVE-2026-55066 | Alta (7.1) | 0.37% | — | 28 ago 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in… |
| CVE-2026-55065 | Alta (8.1) | 0.50% | — | 28 ago 2026 | Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while… |
| CVE-2026-55064 | Media (4.3) | 0.37% | — | 28 ago 2026 | Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting… |
| CVE-2026-54766 | Media (5.3) | 0.43% | — | 28 ago 2026 | Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to… |
| CVE-2026-76216 | Alta (7.7) | 0.36% | — | 19 ago 2026 | Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers… |
| CVE-2026-68582 | Crítica (9.3) | 0.36% | — | 2 ago 2026 | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the… |
| CVE-2026-68581 | Alta (8.6) | 0.46% | — | 2 ago 2026 | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic… |
| CVE-2026-56765 | Crítica (9.3) | 0.51% | — | 10 jul 2026 | Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment… |
| CVE-2026-40103 | Media (5.4) | 0.35% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement for custom project background routes is method-confused. A token with only projects.background can… |
| CVE-2026-35602 | Alta (7.1) | 0.55% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON metadata inside the import zip instead of the actual… |
| CVE-2026-35601 | Media (4.1) | 0.32% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping.… |
| CVE-2026-35600 | Media (5.4) | 0.31% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters.… |
| CVE-2026-35599 | Media (6.5) | 0.58% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current… |
| CVE-2026-35598 | Media (4.3) | 0.35% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user… |
| CVE-2026-35597 | Alta (7.5) | 0.47% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. When a TOTP validation fails, the… |
| CVE-2026-35596 | Media (4.3) | 0.35% | — | 10 abr 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a SQL operator precedence bug that allows any authenticated user to read any label that has at least… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.