CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-40070: bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and is MEDIUM
- CVE-2026-1502: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. MEDIUM
- CVE-2026-3360: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecu HIGH
- CVE-2026-33456: Livestatus injection in the notification test mode in Checkmk MEDIUM
- CVE-2026-35648: OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not r LOW
Related Coverage
Threat Actors