CVE-2026-35595
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires Ca...
Related Vulnerabilities
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-40073: @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass HIGH
- CVE-2026-34479: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden b MEDIUM
- CVE-2026-5996: A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected el CRITICAL
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
Related Coverage
Threat Actors