Vulnerabilidades en go-vikunja

56 resultados
Análisis Vexday

Go-Vikunja apresenta 35 vulnerabilidades catalogadas, das quais 2 são críticas, mas nenhuma está sendo explorada ativamente no cenário atual. A fraqueza dominante (CWE-863 - falha de autorização inadequada) sugere problemas de controle de acesso, exigindo revisão de políticas de permissão. O risco é de moderado a baixo no curto prazo pela ausência de exploração ativa, embora a quantidade de vulnerabilidades demande atenção preventiva.

CVE-2026-33336MEDIUMVikunja Desktop vulnerable to Remote Code Execution via same-window navigationEPSS 1.1%CVE-2026-27819HIGHVikunja has Path Traversal in CLI RestoreEPSS 0.7%CVE-2026-28268CRITICALVikunja Vulnerable to Account Takeover via Password Reset Token ReuseEPSS 0.7%CVE-2026-91973HIGHVikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuthEPSS 0.6%CVE-2026-91972HIGHVikunja before 2.6.0 Authentication Bypass via Unthrottled APIEPSS 0.5%CVE-2026-33668HIGHVikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID ConnectEPSS 0.5%CVE-2026-27616HIGHVikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token ExposureEPSS 0.5%CVE-2026-27575CRITICALVijkunja has Weak Password Policy Combined with Persistent Sessions After Password ChangeEPSS 0.4%CVE-2026-68581HIGHVikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID CollisionEPSS 0.4%CVE-2026-33680HIGHVikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission EscalationEPSS 0.4%CVE-2026-33679MEDIUMVikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF ProtectionsEPSS 0.4%CVE-2026-33334MEDIUMVikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegrationEPSS 0.4%CVE-2026-91985HIGHVikunja before 2.6.0 Privilege Escalation via Link Share HashEPSS 0.4%CVE-2026-91968HIGHvikunja before 2.6.0 Denial of Service via unbounded filter recursionEPSS 0.4%CVE-2026-91970HIGHVikunja before 2.6.0 Resource Exhaustion via Planka MigrationEPSS 0.4%CVE-2026-33316HIGHVikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account DisablementEPSS 0.4%CVE-2026-55065HIGHVikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/apiEPSS 0.3%CVE-2026-35599MEDIUMVikunja has an Algorithmic Complexity DoS in Repeating Task HandlerEPSS 0.3%CVE-2026-91971HIGHVikunja before 2.6.0 Denial of Service via Avatar UploadEPSS 0.3%CVE-2026-35602MEDIUMVikunja has a File Size Limit Bypass via Vikunja ImportEPSS 0.3%