Vendor
Vikunja vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in Vikunja: 0 in the last 7 days and 21 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91985, was published on 15 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 21
- Critical, all time
- 1
- Exploited in the wild
- 0
About Vikunja
Vikunja is an open-source to-do list application for organizing tasks.
Vikunja technologies
- Vikunja32
Latest Vikunja vulnerabilities
- CVE-2026-91985: Vikunja link-share hash disclosure and privilege escalationhighCVSS 7.5EPSS 0.4%
- CVE-2026-91984: Vikunja task-position authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-91983: Vikunja API token scope bypass via expand parametermediumCVSS 4.3EPSS 0.3%
- CVE-2026-91982: Vikunja TOTP secret exposure via unprotected API endpointmediumCVSS 4.3EPSS 0.4%
- CVE-2026-91981: Vikunja user enumeration via v2 API token validation bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-91980: Vikunja team enumeration via project sharemediumCVSS 4.3EPSS 0.3%
- CVE-2026-91979: Vikunja decompression bomb denial of service in data importmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91973: Vikunja authentication bypass in CalDAV BasicAuth endpointshighCVSS 7.5EPSS 0.7%
- CVE-2026-91972: Vikunja API v2 missing rate limiting on authentication endpointshighCVSS 7.5EPSS 0.6%
- CVE-2026-91971: Vikunja avatar and project-background upload denial of servicemediumCVSS 6.5EPSS 0.4%
- CVE-2026-91970: Vikunja resource exhaustion in Planka migratormediumCVSS 6.5EPSS 0.4%
- CVE-2026-91969: vikunja resource exhaustion in CSV migration endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91968: Vikunja task-filter resource exhaustion via unbounded recursionmediumCVSS 6.5EPSS 0.4%
- CVE-2026-55067: Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST…mediumCVSS 5EPSS 0.3%
- CVE-2026-55066: Vikunja task authorization bypass in bucket endpointhighCVSS 7.1EPSS 0.4%
- CVE-2026-55065: Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE…highCVSS 8.1EPSS 0.5%
- CVE-2026-55064: Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin…mediumCVSS 4.3EPSS 0.4%
- CVE-2026-54766: Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation…mediumCVSS 4EPSS 0.4%
- CVE-2026-68582: Vikunja broken object level authorization in task-collection endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-68581: Vikunja API token authentication bypass via link-share ID collisionhighCVSS 8.1EPSS 0.5%
- CVE-2026-56765: Vikunja authorization bypass and IDOR in LinkSharing and TaskAttachmentscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-40103: Vikunja authorization bypass in scoped API tokensmediumCVSS 5.4EPSS 0.4%
- CVE-2026-35602: Vikunja file size limit bypass in import endpointmediumCVSS 5.4EPSS 0.5%
- CVE-2026-35601: Vikunja CRLF injection in CalDAV output generatormediumCVSS 4.1EPSS 0.3%
- CVE-2026-35600: Vikunja Markdown injection in email notificationsmediumCVSS 5.4EPSS 0.3%
Most severe Vikunja vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-56765: Vikunja authorization bypass and IDOR in LinkSharing and TaskAttachmentscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-35595: Vikunja privilege escalation via project reparentinghighCVSS 8.3EPSS 0.5%
- CVE-2026-55065: Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE…highCVSS 8.1EPSS 0.5%
- CVE-2026-68581: Vikunja API token authentication bypass via link-share ID collisionhighCVSS 8.1EPSS 0.5%
- CVE-2026-91973: Vikunja authentication bypass in CalDAV BasicAuth endpointshighCVSS 7.5EPSS 0.7%
- CVE-2026-91972: Vikunja API v2 missing rate limiting on authentication endpointshighCVSS 7.5EPSS 0.6%
- CVE-2026-91985: Vikunja link-share hash disclosure and privilege escalationhighCVSS 7.5EPSS 0.4%
- CVE-2026-34727: Vikunja TOTP two-factor authentication bypass in OIDC callbackhighCVSS 7.4EPSS 0.4%
- CVE-2026-55066: Vikunja task authorization bypass in bucket endpointhighCVSS 7.1EPSS 0.4%
- CVE-2026-35599: Vikunja algorithmic complexity DoS in repeating task handlermediumCVSS 6.5EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 1 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 5 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 13 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/vikunja.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Vikunja vulnerabilities", https://junglewise.ai/threats/vendors/vikunja, 26 September 2026.