VulnSea

vikunja vulnerabilities

CVEs whose affected-version data names the vikunja package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

13 CVEsRSS

CVE-2026-91969Medium· 6.5
6d ago

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions…

Sunlitgo-vikunja · vikunjaEPSS 0.34%via NVD
CVE-2026-91968Medium· 6.5PoC
6d ago

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested pa…

Twilightgo-vikunja · vikunjaEPSS 0.37%via NVD
CVE-2026-91973High· 7.5PoC
6d ago

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well…

Midnightgo-vikunja · vikunjaEPSS 0.61%via NVD
CVE-2026-91970Medium· 6.5PoC
6d ago

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to atta…

Twilightgo-vikunja · vikunjaEPSS 0.37%via NVD
CVE-2026-91980Medium· 4.3PoC
6d ago

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve comp…

Twilightgo-vikunja · vikunjaEPSS 0.27%via NVD
CVE-2026-91972High· 7.5PoC
6d ago

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential gue…

Midnightgo-vikunja · vikunjaEPSS 0.50%via NVD
CVE-2026-91971Medium· 6.5PoC
6d ago

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images wit…

Twilightgo-vikunja · vikunjaEPSS 0.34%via NVD
CVE-2026-91982Medium· 4.3PoC
6d ago

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access toke…

Twilightgo-vikunja · vikunjaEPSS 0.28%via NVD
CVE-2026-91981Medium· 4.3PoC
6d ago

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames ex…

Twilightgo-vikunja · vikunjaEPSS 0.24%via NVD
CVE-2026-91979Medium· 6.5
6d ago

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausti…

Sunlitgo-vikunja · vikunjaEPSS 0.34%via NVD
CVE-2026-91985High· 7.5PoC
6d ago

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-…

Midnightgo-vikunja · vikunjaEPSS 0.38%via NVD
CVE-2026-91983Medium· 4.3PoC
6d ago

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restric…

Twilightgo-vikunja · vikunjaEPSS 0.27%via NVD
CVE-2026-91984Medium· 4.3
6d ago

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST o…

Sunlitgo-vikunja · vikunjaEPSS 0.21%via NVD
vikunja vulnerabilities (CVEs) · VulnSea