{"api_version":"v1","generated_at":"2026-10-09T00:45:00+00:00","product":{"cve_count":56,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-go-vikunja-vikunja-10a1bb9a7153","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"vikunja","next_cursor":"djE6NTA","observations":[{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91985","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91985","fixed":"vikunja: 2.6.0","last_modified":"2026-09-15T16:04:15.007Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-qfwc-vx6f-3g6g","primary_source":"","published":"2026-09-15T15:18:28.282Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91984","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91984","fixed":"vikunja: 2.6.0","last_modified":"2026-09-17T19:27:58.744Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-w39f-h553-h2mx","primary_source":"","published":"2026-09-15T15:18:27.606Z"},{"affected":"vikunja: 1.0.0 < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91983","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91983","fixed":"vikunja: 2.6.0","last_modified":"2026-09-15T15:52:07.941Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-9rg3-v78m-26q8","primary_source":"","published":"2026-09-15T15:18:26.899Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91982","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91982","fixed":"vikunja: 2.6.0","last_modified":"2026-09-17T15:14:33.105Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-88f6-4rjv-x774","primary_source":"","published":"2026-09-15T15:18:26.212Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91981","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91981","fixed":"vikunja: 2.6.0","last_modified":"2026-09-21T18:47:28.550Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-vfxw-3x8p-2vjr","primary_source":"","published":"2026-09-15T15:18:25.523Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91980","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91980","fixed":"vikunja: 2.6.0","last_modified":"2026-09-15T16:03:30.623Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-39p5-2wrr-xh29","primary_source":"","published":"2026-09-15T15:18:24.855Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91979","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91979","fixed":"vikunja: 2.6.0","last_modified":"2026-09-17T19:28:09.001Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-w7jp-mf2v-8342","primary_source":"","published":"2026-09-15T15:18:24.176Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91973","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91973","fixed":"vikunja: 2.6.0","last_modified":"2026-09-15T15:55:04.161Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2","primary_source":"","published":"2026-09-15T15:18:23.488Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91972","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91972","fixed":"vikunja: 2.6.0","last_modified":"2026-09-17T15:12:40.377Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6rvj-qwjf-3m4q","primary_source":"","published":"2026-09-15T15:18:22.792Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91971","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91971","fixed":"vikunja: 2.6.0","last_modified":"2026-09-21T18:48:39.833Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-4vh2-39rq-rq8j","primary_source":"","published":"2026-09-15T15:18:22.129Z"},{"affected":"vikunja: < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91970","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91970","fixed":"vikunja: 2.6.0","last_modified":"2026-09-15T16:02:52.721Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-wq92-8x3r-fm38","primary_source":"","published":"2026-09-15T15:18:21.449Z"},{"affected":"vikunja: 2.5.0 < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91969","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91969","fixed":"vikunja: 2.6.0","last_modified":"2026-09-17T19:28:14.545Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-pqf9-h8g4-8gmh","primary_source":"","published":"2026-09-15T15:18:20.780Z"},{"affected":"vikunja: 2.5.0 < 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-91968","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91968","fixed":"vikunja: 2.6.0","last_modified":"2026-09-15T15:56:07.929Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr","primary_source":"","published":"2026-09-15T15:18:20.097Z"},{"affected":"< 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-55067","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55067","fixed":"2.4.0.","last_modified":"2026-08-28T19:55:24.677Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-569v-q83c-3j3g","primary_source":"","published":"2026-08-28T16:53:59.656Z"},{"affected":"vikunja: < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-55066","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55066","fixed":"2.4.0.","last_modified":"2026-08-31T18:54:28.170Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-5pg6-m483-7vrg","primary_source":"","published":"2026-08-28T16:51:48.114Z"},{"affected":"vikunja: >= 0.24.6, < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-55065","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55065","fixed":"2.4.0.","last_modified":"2026-09-01T01:46:09.120Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-gg93-x632-9ccv","primary_source":"","published":"2026-08-28T16:40:27.706Z"},{"affected":">= 2.3.0, < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-55064","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55064","fixed":"2.4.0.","last_modified":"2026-08-28T20:29:30.143Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-44v6-7fxq-vgf4","primary_source":"","published":"2026-08-28T16:38:38.293Z"},{"affected":">= 0.21.0, < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-54766","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54766","fixed":"2.4.0.","last_modified":"2026-08-28T19:59:25.820Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-f27p-pw2p-9pr4","primary_source":"","published":"2026-08-28T16:36:57.857Z"},{"affected":"vikunja: \u2264 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-76216","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76216","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-20T16:10:29.192Z","patch_url":"","primary_source":"","published":"2026-08-19T14:02:01.282Z"},{"affected":"0.24.0 < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-68582","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68582","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-03T19:57:08.647Z","patch_url":"","primary_source":"","published":"2026-08-02T12:15:28.568Z"},{"affected":"0.22.0 < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-68581","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68581","fixed":"2.4.0.","last_modified":"2026-08-03T15:02:40.435Z","patch_url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-vvcv-vpph-h844","primary_source":"","published":"2026-08-02T12:15:27.893Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-40103","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40103","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-15T14:45:18.303Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/6a0f39b252a81fa4b19dc56dc889183acc9225ae","primary_source":"","published":"2026-04-10T16:12:27.603Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35602","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35602","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-14T14:19:30.140Z","patch_url":"","primary_source":"","published":"2026-04-10T16:10:39.630Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35601","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35601","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-13T15:37:03.974Z","patch_url":"","primary_source":"","published":"2026-04-10T16:08:50.519Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35600","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35600","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-14T15:01:18.724Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/0f3730d045f20e261e3cdfc6d93c325653395b64","primary_source":"","published":"2026-04-10T16:07:07.846Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35599","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35599","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-10T18:28:29.310Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/6df0d6c8f54b01db6464c42810e40e55f12b481b","primary_source":"","published":"2026-04-10T16:05:57.581Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35598","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35598","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-14T14:20:44.249Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/879462d717351fe5d276ddec5246bdec31b41661","primary_source":"","published":"2026-04-10T16:04:32.083Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35597","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35597","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-13T15:37:11.358Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/6ca0151d02fa0e8c7e2181ab916a28e08caaaec8","primary_source":"","published":"2026-04-10T16:03:19.636Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35596","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35596","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-14T14:51:51.537Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/fc216c38afaa51dd56dde7a97343d2148ecf24c1","primary_source":"","published":"2026-04-10T15:59:43.255Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35595","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35595","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-10T18:16:18.230Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/c03d682f48aff890eeb3c8b41d38226069722827","primary_source":"","published":"2026-04-10T15:58:32.658Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-35594","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35594","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-14T14:32:15.339Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/379d8a5c19334ffe4846003f590e202c31a75479","primary_source":"","published":"2026-04-10T15:55:04.929Z"},{"affected":"< 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-34727","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34727","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-13T15:37:32.071Z","patch_url":"","primary_source":"","published":"2026-04-10T15:45:30.662Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33700","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33700","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T18:04:42.445Z","patch_url":"","primary_source":"","published":"2026-03-24T15:51:40.172Z"},{"affected":"< 2.2.2","affected_versions_present":true,"cve_id":"CVE-2026-33680","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33680","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-26T19:52:13.837Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/9efe1fadba817923c7c7f5953c3e9e9c5683bbf3","primary_source":"","published":"2026-03-24T15:47:47.529Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33679","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33679","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T17:34:14.519Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/363aa6642352b08fc8bc6aaff2f3a550393af1cf","primary_source":"","published":"2026-03-24T15:46:10.417Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33678","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33678","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T17:04:42.454Z","patch_url":"","primary_source":"","published":"2026-03-24T15:44:06.336Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33677","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33677","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T17:43:43.803Z","patch_url":"","primary_source":"","published":"2026-03-24T15:36:51.576Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33676","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33676","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T18:55:19.706Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/833f2aec006ac0f6643c41872e45dd79220b9174","primary_source":"","published":"2026-03-24T15:35:37.991Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33675","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33675","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T18:15:30.530Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/93297742236e3d33af72c993e5da960db01d259e","primary_source":"","published":"2026-03-24T15:33:05.868Z"},{"affected":">= 0.18.0, < 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33668","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33668","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-26T19:52:13.977Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/033922309f492996c928122fb49b691339199c35","primary_source":"","published":"2026-03-24T15:30:27.159Z"},{"affected":">= 1.0.0-rc0, < 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33474","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33474","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T15:52:23.050Z","patch_url":"","primary_source":"","published":"2026-03-24T15:21:19.628Z"},{"affected":">= 0.13, < 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-33473","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33473","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T17:11:26.042Z","patch_url":"","primary_source":"","published":"2026-03-24T15:18:14.481Z"},{"affected":">= 0.21.0, < 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33336","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33336","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T17:44:50.761Z","patch_url":"","primary_source":"","published":"2026-03-24T15:16:14.681Z"},{"affected":">= 0.21.0, < 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33335","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33335","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-25T13:41:50.096Z","patch_url":"","primary_source":"","published":"2026-03-24T15:07:41.460Z"},{"affected":">= 0.21.0, < 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33334","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33334","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T18:24:31.238Z","patch_url":"","primary_source":"","published":"2026-03-24T15:02:20.418Z"},{"affected":"< 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33316","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33316","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-26T13:08:08.138Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/049f4a6be46f9460bd516f489ef9f569574bc70d","primary_source":"","published":"2026-03-24T14:59:17.242Z"},{"affected":"< 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33315","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33315","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T15:33:55.744Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/cdf5d30a425d032f749b78b98b828f25ad882615","primary_source":"","published":"2026-03-24T14:53:34.375Z"},{"affected":"< 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33313","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33313","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T17:14:22.348Z","patch_url":"https://github.com/go-vikunja/vikunja/commit/bc6d843ed4df82a6c89f10aa676a7a33d27bf2fd","primary_source":"","published":"2026-03-24T14:50:11.714Z"},{"affected":">= 0.20.2, < 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-33312","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33312","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-20T19:24:20.400Z","patch_url":"","primary_source":"","published":"2026-03-20T14:42:14.137Z"},{"affected":">= 0.8, < 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-29794","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29794","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-20T17:15:23.140Z","patch_url":"","primary_source":"","published":"2026-03-20T14:39:59.035Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"go-vikunja"}}
