CVE-2026-35595
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires Ca...
Related Vulnerabilities
- CVE-2026-35657: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sess HIGH
- CVE-2026-34943: Wasmtime has a possible panic when lifting `flags` component value MEDIUM
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-33704: Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including stu HIGH
- CVE-2026-35195: Wasmtime has out-of-bounds write or crash when transcoding component model strings MEDIUM
Related Coverage
Threat Actors