CVE-2026-25935
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/02/2026
Last modified:
20/02/2026
Description
Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanceTooltip.vue temporarily creates a div and sets the innerHtml to the description. Since there is no escaping on either the server or client side, a malicious user can share a project, create a malicious task, and cause an XSS on hover. This vulnerability is fixed in 1.1.0.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | 1.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



