kolaente
22 exploits
Active since Feb 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVSS 8.1
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVSS 8.1
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVSS 8.1
Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVSS 6.5
Vikunja Affected by Privilege Escalation via Project Reparenting
CVSS 8.3
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVSS 4.3
Vikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout
CVSS 5.9
Vikunja has Missing Authorization on CalDAV Task Read
CVSS 4.3
Vikunja <2.3.0 Repeating Task Handler - Denial of Service
CVSS 6.5
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
CVSS 5.4
Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
CVSS 4.3
Vikunja <2.2.0 Task Comments - Insecure Direct Object Reference
CVSS 4.3
Vikunja <2.2.0 CalDAV Basic Auth - Two-Factor Authentication Bypass
CVSS 4.3
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVSS 8.1
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources
CVSS 6.4
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read
CVSS 6.5
Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections
CVSS 6.4
Vikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation
CVSS 7.5
Vikunja < 2.1.0 - Persistent Account Takeover via Password Reset Token Reuse
CVSS 9.8
vikunja/vikunja < 1.1.0 - Stored Cross-Site Scripting via Task Description Hover
CVSS 5.4