Technology · Go
code.vikunja.io/api (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 38 vulnerabilities in code.vikunja.io/api (Go): 0 in the last 7 days and 6 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55067, was published on 28 August 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 1
- Exploited in the wild
- 0
About code.vikunja.io/api (Go)
The backend API for the Vikunja to-do list application.
Latest code.vikunja.io/api (Go) vulnerabilities
- CVE-2026-55067: Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST…mediumCVSS 5EPSS 0.3%
- CVE-2026-55066: Vikunja task authorization bypass in bucket endpointhighCVSS 7.1EPSS 0.4%
- CVE-2026-55065: Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE…highCVSS 8.1EPSS 0.5%
- CVE-2026-55064: Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin…mediumCVSS 4.3EPSS 0.4%
- CVE-2026-54766: Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation…mediumCVSS 4EPSS 0.4%
- CVE-2026-56765: Vikunja authorization bypass and IDOR in LinkSharing and TaskAttachmentscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-40103: Vikunja authorization bypass in scoped API tokensmediumCVSS 5.4EPSS 0.4%
- CVE-2026-35602: Vikunja file size limit bypass in import endpointmediumCVSS 5.4EPSS 0.5%
- CVE-2026-35601: Vikunja CRLF injection in CalDAV output generatormediumCVSS 4.1EPSS 0.3%
- CVE-2026-35600: Vikunja Markdown injection in email notificationsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-35599: Vikunja algorithmic complexity DoS in repeating task handlermediumCVSS 6.5EPSS 0.6%
- CVE-2026-35598: Vikunja missing authorization in CalDAV task retrievalmediumCVSS 4.3EPSS 0.4%
- CVE-2026-35597: Vikunja TOTP account lockout bypass via database rollbackmediumCVSS 5.9EPSS 0.5%
- CVE-2026-35596: Vikunja incorrect authorization via SQL operator precedence in labelsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-35595: Vikunja privilege escalation via project reparentinghighCVSS 8.3EPSS 0.5%
- CVE-2026-35594: Vikunja insufficient session expiration in link share authenticationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-34727: Vikunja TOTP two-factor authentication bypass in OIDC callbackhighCVSS 7.4EPSS 0.4%
- CVE-2026-33675: GO-2026-4851 - Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network…lowCVSS 3.1EPSS 0.4%
- CVE-2026-33679: GO-2026-4852 - Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/apilowCVSS 3.1EPSS 0.4%
- CVE-2026-33678: GO-2026-4853 - Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/apilowCVSS 3.1EPSS 0.4%
- CVE-2026-33680: GO-2026-4848 - Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/apilowCVSS 3.1EPSS 0.5%
- CVE-2026-33676: GO-2026-4847 - Vikunja has Cross-Project Information Disclosure via Task Relations , Missing Authorization Check on…lowCVSS 3.1EPSS 0.4%
- CVE-2026-33700: GO-2026-4850 - Vikunja has a Link Share Delete IDOR , Missing Project Ownership Check Allows Cross-Project Link Share…mediumCVSS 4EPSS 0.3%
- CVE-2026-33677: GO-2026-4846 - Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in…lowCVSS 3.1EPSS 0.4%
- CVE-2026-33668: GO-2026-4849 - Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in…mediumCVSS 4EPSS 0.6%
Most severe code.vikunja.io/api (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-56765: Vikunja authorization bypass and IDOR in LinkSharing and TaskAttachmentscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-35595: Vikunja privilege escalation via project reparentinghighCVSS 8.3EPSS 0.5%
- CVE-2026-55065: Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE…highCVSS 8.1EPSS 0.5%
- CVE-2026-34727: Vikunja TOTP two-factor authentication bypass in OIDC callbackhighCVSS 7.4EPSS 0.4%
- CVE-2026-55066: Vikunja task authorization bypass in bucket endpointhighCVSS 7.1EPSS 0.4%
- CVE-2026-35599: Vikunja algorithmic complexity DoS in repeating task handlermediumCVSS 6.5EPSS 0.6%
- CVE-2026-35594: Vikunja insufficient session expiration in link share authenticationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-35597: Vikunja TOTP account lockout bypass via database rollbackmediumCVSS 5.9EPSS 0.5%
- CVE-2026-35602: Vikunja file size limit bypass in import endpointmediumCVSS 5.4EPSS 0.5%
- CVE-2026-40103: Vikunja authorization bypass in scoped API tokensmediumCVSS 5.4EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 1 | 1 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 5 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/code-vikunja-io-api.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "code.vikunja.io/api (Go) vulnerabilities", https://junglewise.ai/threats/technologies/code-vikunja-io-api, 28 September 2026.