api has 10 CVEs on record. Cadence is steady at roughly 5 per quarter. The busiest recent month was August 2026 with 5. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 4
Worst active — by depth score
CVE-2026-56765Critical· 9.1Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR50CVE-2026-55065High· 8.1Vikunja is an open-source self-hosted task management platform45CVE-2026-34727High· 7.4Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path41CVE-2026-55066High· 7.1Vikunja is an open-source self-hosted task management platform39CVE-2026-35594Medium· 6.5Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade36
api vulnerabilities
CVEs affecting api, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-54766MediumVikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplica…
CVE-2026-55064Medium· 4.3Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to…
CVE-2026-55065High· 8.1Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only a…
CVE-2026-55066High· 7.1Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket…
CVE-2026-55067Medium· 5.0Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/model…
CVE-2026-35596Medium· 4.3Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVE-2026-35597Medium· 5.9Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
CVE-2026-35594Medium· 6.5Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE-2026-34727High· 7.4Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE-2026-56765Critical· 9.1Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR