Go-vikunja
56 CVEs tracked since 2026. Since Feb 2026, none of them reached CISA KEV.
Go-vikunja CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-02 | 6 | 0 |
| 2026-03 | 18 | 0 |
| 2026-04 | 11 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | null or fewer | |
| 2026-08 | 8 | 0 |
| 2026-09 | 13 | 0 |
Products
The products that kept showing up in Go-vikunja's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Go-vikunja.
- CVE-2026-91985Vikunja before 2.6.0 Privilege Escalation via Link Share Hash7.5
- CVE-2026-91984Vikunja before 2.6.0 Broken Object-Level Authorization via task-position4.3
- CVE-2026-91983Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter4.3
- CVE-2026-91982Vikunja before 2.6.0 TOTP Secret Disclosure via API4.3
- CVE-2026-91981Vikunja before 2.6.0 User Enumeration via v2 API4.3
- CVE-2026-91980vikunja before 2.6.0 Team Enumeration via Project Share4.3
- CVE-2026-91979Vikunja before 2.6.0 Denial of Service via Decompression Bomb6.5
- CVE-2026-91973Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth7.5
- CVE-2026-91972Vikunja before 2.6.0 Authentication Bypass via Unthrottled API7.5
- CVE-2026-91971Vikunja before 2.6.0 Denial of Service via Avatar Upload6.5
- CVE-2026-91970Vikunja before 2.6.0 Resource Exhaustion via Planka Migration6.5
- CVE-2026-91968vikunja before 2.6.0 Denial of Service via unbounded filter recursion6.5
- CVE-2026-91969vikunja before 2.6.0 Resource Exhaustion via CSV Migration6.5
- CVE-2026-55067Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment5.0
- CVE-2026-55066Vikunja: Cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id7.1
The record
- Peak rank
- #64 in Mar 2026
- Busiest month shown
- Mar 2026, 18 CVEs
- Months with a KEV entry
- 0 since Feb 2026
- Monthly snapshots
- 5 since 2026