CVE-2026-34727
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the ma...
Related Vulnerabilities
- CVE-2026-6004: A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown MEDIUM
- CVE-2026-40190: LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in I MEDIUM
- CVE-2026-5991: A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtra HIGH
- CVE-2026-5501: wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the HIGH
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
Related Coverage
Threat Actors