Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vikunja

First CVE: Feb 11, 2026Active for: 1 yearTotal CVEs: 36
33.4
VTI Score
Medium

Vikunja is an open-source project management and task-collaboration platform that, despite a narrow product footprint, occupies a notable position in the landscape of self-hosted productivity tools. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster consistently around web-application layer weaknesses, particularly cross-site scripting, authorization bypass, and authentication flaws that reflect the access-control and input-handling demands of a multi-user task-management system. The recurring exposure across these authentication and authorization classes underscores a structural pattern in web-application security: improper boundary enforcement between user contexts and insufficient validation of request legitimacy, both of which are high-value targets in collaborative platforms where privilege escalation or cross-user data leakage poses significant risk. Defenders deploying Vikunja in production should prioritize patching cycles closely, implement network segmentation around instances holding sensitive work data, and monitor for authentication-bypass exploitation chains. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
36.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vikunja over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2026
5 months ago
Most Recent CVE
Jul 10, 2026
14 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-56765CRITICAL
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-l
Jul 10, 20269.841NONO
CVE-2026-28268CRITICAL
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api th
Feb 27, 20269.834NONO
CVE-2026-27575CRITICAL
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing
Feb 25, 20269.132NONO
CVE-2026-33334CRITICAL
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration
Mar 24, 20269.629NONO
CVE-2026-35595HIGH
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new p
Apr 10, 20268.328NONO
CVE-2026-34727CRITICAL
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP
Apr 10, 20269.128NONO
CVE-2026-33678HIGH
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the tas
Mar 24, 20268.128NONO
CVE-2026-33336HIGH
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration
Mar 24, 20268.828NONO
CVE-2026-33316HIGH
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their acc
Mar 24, 20268.127NONO
CVE-2026-33668HIGH
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check i
Mar 24, 20268.126NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
56%
31%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (75.0%)
Unknown0 (0.0%)
Required9 (25.0%)
Privileges Required
Low24 (66.7%)
High2 (5.6%)
None10 (27.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vikunja.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vikunja — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vikunja's Products

View all 2 CNAs →

Top CWEs