Vikunja is an open-source project management and task-collaboration platform that, despite a narrow product footprint, occupies a notable position in the landscape of self-hosted productivity tools. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster consistently around web-application layer weaknesses, particularly cross-site scripting, authorization bypass, and authentication flaws that reflect the access-control and input-handling demands of a multi-user task-management system. The recurring exposure across these authentication and authorization classes underscores a structural pattern in web-application security: improper boundary enforcement between user contexts and insufficient validation of request legitimacy, both of which are high-value targets in collaborative platforms where privilege escalation or cross-user data leakage poses significant risk. Defenders deploying Vikunja in production should prioritize patching cycles closely, implement network segmentation around instances holding sensitive work data, and monitor for authentication-bypass exploitation chains. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vikunja over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56765CRITICAL Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-l | Jul 10, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-28268CRITICAL Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api th | Feb 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-27575CRITICAL Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing | Feb 25, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-33334CRITICAL Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration | Mar 24, 2026 | 9.6 | 29 | NO | NO |
CVE-2026-35595HIGH Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new p | Apr 10, 2026 | 8.3 | 28 | NO | NO |
CVE-2026-34727CRITICAL Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP | Apr 10, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-33678HIGH Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the tas | Mar 24, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-33336HIGH Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration | Mar 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-33316HIGH Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their acc | Mar 24, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-33668HIGH Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check i | Mar 24, 2026 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vikunja.
Media articles that mention a CVE ID that affects a product developed by Vikunja — matched by CVE ID, not by vendor name.