{"schema_version":1,"title":"code.vikunja.io/api (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 38 vulnerabilities in code.vikunja.io/api (Go): 0 in the last 7 days and 6 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55067, was published on 28 August 2026.","url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api","json_url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/code-vikunja-io-api","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":38,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":6,"last_365_days":38},"latest":[{"cve":"CVE-2026-55067","cvss":5,"epss":0.0034,"slug":"cve-2026-55067-vikunja-kanban-bucket-cross-tenant-relocation-via-mass-assignment","title":"Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket","severity":"medium","exploited":false,"published_at":"2026-08-28T20:18:24.037+00:00","url":"https://junglewise.ai/threats/cve-2026-55067-vikunja-kanban-bucket-cross-tenant-relocation-via-mass-assignment"},{"cve":"CVE-2026-55066","cvss":7.1,"epss":0.0037,"slug":"cve-2026-55066-vikunja-task-authorization-bypass-in-bucket-endpoint","title":"Vikunja task authorization bypass in bucket endpoint","severity":"high","exploited":false,"published_at":"2026-08-28T20:18:23.897+00:00","url":"https://junglewise.ai/threats/cve-2026-55066-vikunja-task-authorization-bypass-in-bucket-endpoint"},{"cve":"CVE-2026-55065","cvss":8.1,"epss":0.005,"slug":"cve-2026-55065-vikunja-authorization-bypass-in-project-view-deletion","title":"Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permit","severity":"high","exploited":false,"published_at":"2026-08-28T20:18:23.757+00:00","url":"https://junglewise.ai/threats/cve-2026-55065-vikunja-authorization-bypass-in-project-view-deletion"},{"cve":"CVE-2026-55064","cvss":4.3,"epss":0.0037,"slug":"cve-2026-55064-vikunja-incomplete-privilege-escalation-fix-via-parent-project-id","title":"Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shar","severity":"medium","exploited":false,"published_at":"2026-08-28T20:18:23.613+00:00","url":"https://junglewise.ai/threats/cve-2026-55064-vikunja-incomplete-privilege-escalation-fix-via-parent-project-id"},{"cve":"CVE-2026-54766","cvss":4,"epss":0.0043,"slug":"cve-2026-54766-vikunja-project-duplication-authorization-bypass","title":"Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/pro","severity":"medium","exploited":false,"published_at":"2026-08-28T20:18:17.803+00:00","url":"https://junglewise.ai/threats/cve-2026-54766-vikunja-project-duplication-authorization-bypass"},{"cve":"CVE-2026-56765","cvss":9.8,"epss":0.0051,"slug":"cve-2026-56765-vikunja-authorization-bypass-and-idor-in-linksharing-and","title":"Vikunja authorization bypass and IDOR in LinkSharing and TaskAttachments","severity":"critical","exploited":false,"published_at":"2026-07-10T15:16:43.727+00:00","url":"https://junglewise.ai/threats/cve-2026-56765-vikunja-authorization-bypass-and-idor-in-linksharing-and"},{"cve":"CVE-2026-40103","cvss":5.4,"epss":0.0035,"slug":"cve-2026-40103-vikunja-authorization-bypass-in-scoped-api-tokens","title":"Vikunja authorization bypass in scoped API tokens","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:13.143+00:00","url":"https://junglewise.ai/threats/cve-2026-40103-vikunja-authorization-bypass-in-scoped-api-tokens"},{"cve":"CVE-2026-35602","cvss":5.4,"epss":0.0055,"slug":"cve-2026-35602-vikunja-file-size-limit-bypass-in-import-endpoint","title":"Vikunja file size limit bypass in import endpoint","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.993+00:00","url":"https://junglewise.ai/threats/cve-2026-35602-vikunja-file-size-limit-bypass-in-import-endpoint"},{"cve":"CVE-2026-35601","cvss":4.1,"epss":0.0032,"slug":"cve-2026-35601-vikunja-crlf-injection-in-caldav-output-generator","title":"Vikunja CRLF injection in CalDAV output generator","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.837+00:00","url":"https://junglewise.ai/threats/cve-2026-35601-vikunja-crlf-injection-in-caldav-output-generator"},{"cve":"CVE-2026-35600","cvss":5.4,"epss":0.0031,"slug":"cve-2026-35600-vikunja-markdown-injection-in-email-notifications","title":"Vikunja Markdown injection in email notifications","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.68+00:00","url":"https://junglewise.ai/threats/cve-2026-35600-vikunja-markdown-injection-in-email-notifications"},{"cve":"CVE-2026-35599","cvss":6.5,"epss":0.0058,"slug":"cve-2026-35599-vikunja-algorithmic-complexity-dos-in-repeating-task-handler","title":"Vikunja algorithmic complexity DoS in repeating task handler","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.52+00:00","url":"https://junglewise.ai/threats/cve-2026-35599-vikunja-algorithmic-complexity-dos-in-repeating-task-handler"},{"cve":"CVE-2026-35598","cvss":4.3,"epss":0.0035,"slug":"cve-2026-35598-vikunja-missing-authorization-in-caldav-task-retrieval","title":"Vikunja missing authorization in CalDAV task retrieval","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.37+00:00","url":"https://junglewise.ai/threats/cve-2026-35598-vikunja-missing-authorization-in-caldav-task-retrieval"},{"cve":"CVE-2026-35597","cvss":5.9,"epss":0.0047,"slug":"cve-2026-35597-vikunja-totp-account-lockout-bypass-via-database-rollback","title":"Vikunja TOTP account lockout bypass via database rollback","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.217+00:00","url":"https://junglewise.ai/threats/cve-2026-35597-vikunja-totp-account-lockout-bypass-via-database-rollback"},{"cve":"CVE-2026-35596","cvss":4.3,"epss":0.0035,"slug":"cve-2026-35596-vikunja-incorrect-authorization-via-sql-operator-precedence-in","title":"Vikunja incorrect authorization via SQL operator precedence in labels","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.067+00:00","url":"https://junglewise.ai/threats/cve-2026-35596-vikunja-incorrect-authorization-via-sql-operator-precedence-in"},{"cve":"CVE-2026-35595","cvss":8.3,"epss":0.0046,"slug":"cve-2026-35595-vikunja-privilege-escalation-via-project-reparenting","title":"Vikunja privilege escalation via project reparenting","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:02.91+00:00","url":"https://junglewise.ai/threats/cve-2026-35595-vikunja-privilege-escalation-via-project-reparenting"},{"cve":"CVE-2026-35594","cvss":6.5,"epss":0.0044,"slug":"cve-2026-35594-vikunja-insufficient-session-expiration-in-link-share","title":"Vikunja insufficient session expiration in link share authentication","severity":"medium","exploited":false,"published_at":"2026-04-10T16:16:32+00:00","url":"https://junglewise.ai/threats/cve-2026-35594-vikunja-insufficient-session-expiration-in-link-share"},{"cve":"CVE-2026-34727","cvss":7.4,"epss":0.0042,"slug":"cve-2026-34727-vikunja-totp-two-factor-authentication-bypass-in-oidc-callback","title":"Vikunja TOTP two-factor authentication bypass in OIDC callback","severity":"high","exploited":false,"published_at":"2026-04-10T16:16:31.853+00:00","url":"https://junglewise.ai/threats/cve-2026-34727-vikunja-totp-two-factor-authentication-bypass-in-oidc-callback"},{"cve":"CVE-2026-33675","cvss":3.1,"epss":0.0039,"slug":"cve-2026-33675-vikunja-has-ssrf-via-todoist-trello-migration-file-attachment","title":"GO-2026-4851 - Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api","severity":"low","exploited":false,"published_at":"2026-03-26T20:33:09+00:00","url":"https://junglewise.ai/threats/cve-2026-33675-vikunja-has-ssrf-via-todoist-trello-migration-file-attachment"},{"cve":"CVE-2026-33679","cvss":3.1,"epss":0.0045,"slug":"cve-2026-33679-vikjuna-bypasses-webhook-ssrf-protections-during-openid-connect","title":"GO-2026-4852 - Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api","severity":"low","exploited":false,"published_at":"2026-03-26T20:33:09+00:00","url":"https://junglewise.ai/threats/cve-2026-33679-vikjuna-bypasses-webhook-ssrf-protections-during-openid-connect"},{"cve":"CVE-2026-33678","cvss":3.1,"epss":0.0038,"slug":"cve-2026-33678-vikjuna-idor-in-task-attachment-readone-allows-cross-project-file","title":"GO-2026-4853 - Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api","severity":"low","exploited":false,"published_at":"2026-03-26T20:33:09+00:00","url":"https://junglewise.ai/threats/cve-2026-33678-vikjuna-idor-in-task-attachment-readone-allows-cross-project-file"},{"cve":"CVE-2026-33680","cvss":3.1,"epss":0.0046,"slug":"cve-2026-33680-vikjuna-link-share-hash-disclosure-via-readall-endpoint-enables","title":"GO-2026-4848 - Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api","severity":"low","exploited":false,"published_at":"2026-03-26T20:33:05+00:00","url":"https://junglewise.ai/threats/cve-2026-33680-vikjuna-link-share-hash-disclosure-via-readall-endpoint-enables"},{"cve":"CVE-2026-33676","cvss":3.1,"epss":0.0042,"slug":"cve-2026-33676-vikunja-has-cross-project-information-disclosure-via-task","title":"GO-2026-4847 - Vikunja has Cross-Project Information Disclosure via Task Relations , Missing Authorization Check on Related Task Read in code.vikunja.io/ap","severity":"low","exploited":false,"published_at":"2026-03-26T20:33:05+00:00","url":"https://junglewise.ai/threats/cve-2026-33676-vikunja-has-cross-project-information-disclosure-via-task"},{"cve":"CVE-2026-33700","cvss":4,"epss":0.0034,"slug":"cve-2026-33700-vikunja-has-a-link-share-delete-idor-missing-project-ownership","title":"GO-2026-4850 - Vikunja has a Link Share Delete IDOR , Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api","severity":"medium","exploited":false,"published_at":"2026-03-26T20:33:05+00:00","url":"https://junglewise.ai/threats/cve-2026-33700-vikunja-has-a-link-share-delete-idor-missing-project-ownership"},{"cve":"CVE-2026-33677","cvss":3.1,"epss":0.0041,"slug":"cve-2026-33677-vikjuna-webhook-basicauth-credentials-exposed-to-read-only","title":"GO-2026-4846 - Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api","severity":"low","exploited":false,"published_at":"2026-03-26T20:33:05+00:00","url":"https://junglewise.ai/threats/cve-2026-33677-vikjuna-webhook-basicauth-credentials-exposed-to-read-only"},{"cve":"CVE-2026-33668","cvss":4,"epss":0.0059,"slug":"cve-2026-33668-vikunja-allows-disabled-locked-user-accounts-to-authenticate-via","title":"GO-2026-4849 - Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api","severity":"medium","exploited":false,"published_at":"2026-03-26T20:33:05+00:00","url":"https://junglewise.ai/threats/cve-2026-33668-vikunja-allows-disabled-locked-user-accounts-to-authenticate-via"}],"weekly":[{"week":"2026-07-06","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://vikunja.io/","repo_url":"https://code.vikunja.io/api","description":"The backend API for the Vikunja to-do list application.","url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},"most_severe":[{"cve":"CVE-2026-56765","cvss":9.8,"epss":0.0051,"slug":"cve-2026-56765-vikunja-authorization-bypass-and-idor-in-linksharing-and","title":"Vikunja authorization bypass and IDOR in LinkSharing and TaskAttachments","severity":"critical","exploited":false,"published_at":"2026-07-10T15:16:43.727+00:00","url":"https://junglewise.ai/threats/cve-2026-56765-vikunja-authorization-bypass-and-idor-in-linksharing-and"},{"cve":"CVE-2026-35595","cvss":8.3,"epss":0.0046,"slug":"cve-2026-35595-vikunja-privilege-escalation-via-project-reparenting","title":"Vikunja privilege escalation via project reparenting","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:02.91+00:00","url":"https://junglewise.ai/threats/cve-2026-35595-vikunja-privilege-escalation-via-project-reparenting"},{"cve":"CVE-2026-55065","cvss":8.1,"epss":0.005,"slug":"cve-2026-55065-vikunja-authorization-bypass-in-project-view-deletion","title":"Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permit","severity":"high","exploited":false,"published_at":"2026-08-28T20:18:23.757+00:00","url":"https://junglewise.ai/threats/cve-2026-55065-vikunja-authorization-bypass-in-project-view-deletion"},{"cve":"CVE-2026-34727","cvss":7.4,"epss":0.0042,"slug":"cve-2026-34727-vikunja-totp-two-factor-authentication-bypass-in-oidc-callback","title":"Vikunja TOTP two-factor authentication bypass in OIDC callback","severity":"high","exploited":false,"published_at":"2026-04-10T16:16:31.853+00:00","url":"https://junglewise.ai/threats/cve-2026-34727-vikunja-totp-two-factor-authentication-bypass-in-oidc-callback"},{"cve":"CVE-2026-55066","cvss":7.1,"epss":0.0037,"slug":"cve-2026-55066-vikunja-task-authorization-bypass-in-bucket-endpoint","title":"Vikunja task authorization bypass in bucket endpoint","severity":"high","exploited":false,"published_at":"2026-08-28T20:18:23.897+00:00","url":"https://junglewise.ai/threats/cve-2026-55066-vikunja-task-authorization-bypass-in-bucket-endpoint"},{"cve":"CVE-2026-35599","cvss":6.5,"epss":0.0058,"slug":"cve-2026-35599-vikunja-algorithmic-complexity-dos-in-repeating-task-handler","title":"Vikunja algorithmic complexity DoS in repeating task handler","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.52+00:00","url":"https://junglewise.ai/threats/cve-2026-35599-vikunja-algorithmic-complexity-dos-in-repeating-task-handler"},{"cve":"CVE-2026-35594","cvss":6.5,"epss":0.0044,"slug":"cve-2026-35594-vikunja-insufficient-session-expiration-in-link-share","title":"Vikunja insufficient session expiration in link share authentication","severity":"medium","exploited":false,"published_at":"2026-04-10T16:16:32+00:00","url":"https://junglewise.ai/threats/cve-2026-35594-vikunja-insufficient-session-expiration-in-link-share"},{"cve":"CVE-2026-35597","cvss":5.9,"epss":0.0047,"slug":"cve-2026-35597-vikunja-totp-account-lockout-bypass-via-database-rollback","title":"Vikunja TOTP account lockout bypass via database rollback","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.217+00:00","url":"https://junglewise.ai/threats/cve-2026-35597-vikunja-totp-account-lockout-bypass-via-database-rollback"},{"cve":"CVE-2026-35602","cvss":5.4,"epss":0.0055,"slug":"cve-2026-35602-vikunja-file-size-limit-bypass-in-import-endpoint","title":"Vikunja file size limit bypass in import endpoint","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:03.993+00:00","url":"https://junglewise.ai/threats/cve-2026-35602-vikunja-file-size-limit-bypass-in-import-endpoint"},{"cve":"CVE-2026-40103","cvss":5.4,"epss":0.0035,"slug":"cve-2026-40103-vikunja-authorization-bypass-in-scoped-api-tokens","title":"Vikunja authorization bypass in scoped API tokens","severity":"medium","exploited":false,"published_at":"2026-04-10T17:17:13.143+00:00","url":"https://junglewise.ai/threats/cve-2026-40103-vikunja-authorization-bypass-in-scoped-api-tokens"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}