CVE-2026-34727
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the ma...
Related Vulnerabilities
- CVE-2026-34478: Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424L MEDIUM
- CVE-2026-5460: A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare pr MEDIUM
- CVE-2026-39922: GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnera N/A
- CVE-2026-3371: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure MEDIUM
- CVE-2026-35647: OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass MEDIUM
Related Coverage
Threat Actors