9.1

CVSS3.1

CVE-2026-33340 - LoLLMs WEBUI has unauthenticated Server-Side Request Forgery (SSRF) in /api/proxy endpoint

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attacke…

πŸ“… Published: March 24, 2026, 3:58 p.m. πŸ”„ Last Modified: April 21, 2026, 11:45 p.m.

6.9

CVSS4.0

CVE-2026-33700 - Vikunja has a Link Share Delete IDOR β€” Missing Project Ownership Check Allows Cross-Project Link Sh…

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:project/shares/:share` endpoint does not verify that the link share belongs to the project specified in the URL. An attacker with admin access to any project can delete link shares …

πŸ“… Published: March 24, 2026, 3:51 p.m. πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

7.5

CVSS3.1

CVE-2026-33680 - Vikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method allows link share authenticated users to list all link shares for a project, including their secret hashes. While `LinkSharing.CanRead()` correctly blocks link share users from…

πŸ“… Published: March 24, 2026, 3:47 p.m. πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

6.4

CVSS3.1

CVE-2026-33679 - Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls…

πŸ“… Published: March 24, 2026, 3:46 p.m. πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

8.1

CVSS3.1

CVE-2026-33678 - Vikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the task ID from the URL path. The permission check in `CanRead()` validates access to the task specified in the URL, but `Rea…

πŸ“… Published: March 24, 2026, 3:44 p.m. πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

6.5

CVSS3.1

CVE-2026-33677 - Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the exist…

πŸ“… Published: March 24, 2026, 3:36 p.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-33676 - Vikunja has Cross-Project Information Disclosure via Task Relations β€” Missing Authorization Check o…

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related_tasks` field with full task objects for all related tasks without checking whether the requesting user has read permission on those tasks' projects. …

πŸ“… Published: March 24, 2026, 3:35 p.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

6.4

CVSS3.1

CVE-2026-33675 - Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Net…

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `DownloadFile` and `DownloadFileWithHeaders` in `pkg/modules/migration/helpers.go` make arbitrary HTTP GET requests without any SSRF protection. When a user triggers a Todoist or T…

πŸ“… Published: March 24, 2026, 3:33 p.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

7.1

CVSS4.0

CVE-2026-33668 - Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Con…

Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths β€” API tokens, CalDAV b…

πŸ“… Published: March 24, 2026, 3:30 p.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-33474 - Vikunja Affected by DoS via Image Preview Generation

Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0, unbounded image decoding and resizing during preview generation lets an attacker exhaust CPU and memory with highly compressed but extremely large-dimension images. Version 2.2.…

πŸ“… Published: March 24, 2026, 3:21 p.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.
Total resulsts: 349182
Page 941 of 34,919
Β« previous page Β» next page
Filters