CVE-2026-27616 – Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token Exposure
CVE ID : CVE-2026-27616
Published : Feb. 25, 2026, 10:16 p.m. | 52 minutes ago
Description : Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports JavaScript execution through elements such as