CVE-2026-40103
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement for custom project background routes is ...
Related Vulnerabilities
- CVE-2026-35600: Vikunja has HTML Injection via Task Titles in Overdue Email Notifications MEDIUM
- CVE-2026-5996: A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected el CRITICAL
- CVE-2026-5479: In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and r HIGH
- CVE-2026-40189: goshs has a file-based ACL authorization bypass in goshs state-changing routes CRITICAL
- CVE-2026-34988: Wasmtime has data leakage between pooling allocator instances MEDIUM
Related Coverage
Threat Actors