Donetick is a task and checklist management application with a focused vulnerability footprint centered on configuration and initialization practices. The observed weakness classes—insecure default configuration and insecure variable initialization—reflect common patterns in application deployment where security-sensitive settings require explicit hardening by administrators and developers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Donetick over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47945CRITICAL Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak | May 17, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Donetick.
Media articles that mention a CVE ID that affects a product developed by Donetick — matched by CVE ID, not by vendor name.