CVE-2026-25935 | go-vikunja up to 1.0.x TaskGlanceTooltip.vue cross site scripting (GHSA-m4g2-2q66-vc9v)
A vulnerability was found in go-vikunja vikunja up to 1.0.x. It has been classified as problematic. This impacts the function TaskGlanceTooltip.vue. Performing a manipulation results in basic cross site scripting.
This vulnerability is identified as CVE-2026-25935. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.