Vikunja

vikunja.io
Vikunja

Vikunja is an open-source to-do application. It is suitable for a wide variety of projects, supporting List, Gantt, Table and Kanban views to visualize all tasks in different contexts. For collaboration, it has sharing support via private teams or public links. It can be self-hosted or used as a managed service for a small fee.

Open Source

Vikunja Source Code

Author

go-vikunja

Description

The task manager you actually own.

#api#golang#project-management#self-hosted#todo#todoapp#todolist#vuejs

Homepage

https://vikunja.io

License

AGPL-3.0

Created

28 Nov 18

Last Updated

12 Jul 26

Latest version

vue3

Primary Language

Go

Size

82,874 KB

Stars

4,737

Forks

540

Watchers

4,737

Language Usage

Language Usage

Star History

Star History

Top Contributors

Recent Commits

  • renovate[bot] (12 Jul 26)

    fix(deps): update module github.com/yuin/goldmark to v1.8.4

  • Tink (11 Jul 26)

    fix(attachments): keep blob mime type so pdf previews open inline (#3157)

  • Tink (11 Jul 26)

    fix(postgres): resolve all statements against the configured schema (#3156)

  • TowyTowy (11 Jul 26)

    fix(caldav): compute VTODO DURATION components correctly (#3155)

  • renovate[bot] (11 Jul 26)

    chore(deps): update dev-dependencies

  • renovate[bot] (10 Jul 26)

    fix(deps): update dependency @sentry/vue to v10.64.0

  • kolaente (10 Jul 26)

    feat(auth): add OpenID provider availability monitoring and retry logic (#3145)

  • Tink (10 Jul 26)

    fix(notifications): queue mails only after the notification row is committed (#3150)

  • renovate[bot] (10 Jul 26)

    fix(deps): update tiptap to v3.27.3

  • renovate[bot] (10 Jul 26)

    chore(deps): update actions/stale action to v10.4.0

  • renovate[bot] (10 Jul 26)

    chore(deps): update dev-dependencies

  • renovate[bot] (09 Jul 26)

    chore(deps): update cachix/install-nix-action action to v31.10.7

  • kolaente (09 Jul 26)

    fix(cli): drain the mail queue before user commands exit Mail sending is asynchronous: SendMail only enqueues the message and a background daemon goroutine performs the actual SMTP delivery. CLI commands exited as soon as their run function returned, killing the daemon before the handshake completed, so `user reset-password`, `user delete` and `user create` reported success without ever sending their mail. Add mail.StopMailDaemon which closes the queue and blocks until the daemon has delivered all remaining messages (with a timeout so a broken SMTP server can't hang the CLI), and call it from a PersistentPostRun hook on the user command. The web server's non-blocking behavior is unchanged.

  • renovate[bot] (09 Jul 26)

    fix(deps): update module github.com/coreos/go-oidc/v3 to v3.20.0

  • renovate[bot] (09 Jul 26)

    fix(deps): update module github.com/wneessen/go-mail to v0.8.1

  • kolaente (09 Jul 26)

    Extract golangci-lint setup into reusable action (#3142)

  • renovate[bot] (09 Jul 26)

    fix(deps): update module golang.org/x/net to v0.57.0

  • renovate[bot] (09 Jul 26)

    fix(deps): update tiptap to v3.27.2

  • renovate[bot] (09 Jul 26)

    fix(deps): update module golang.org/x/term to v0.45.0

  • renovate[bot] (08 Jul 26)

    chore(deps): update dependency undici@6 to v8.7.0

  • renovate[bot] (09 Jul 26)

    fix(deps): update aws-sdk-go-v2 monorepo

  • renovate[bot] (09 Jul 26)

    fix(deps): update module golang.org/x/image to v0.44.0

  • renovate[bot] (08 Jul 26)

    chore(deps): update postgres:18 docker digest to 22c89fe

  • renovate[bot] (08 Jul 26)

    fix(deps): update module golang.org/x/sync to v0.22.0

  • renovate[bot] (08 Jul 26)

    fix(deps): update module golang.org/x/sys to v0.47.0

  • renovate[bot] (07 Jul 26)

    chore(deps): update dependency undici@7 to v8.7.0

  • renovate[bot] (07 Jul 26)

    chore(deps): update postgres:18 docker digest to 3111367

  • renovate[bot] (08 Jul 26)

    chore(deps): update dependency go to v1.26.5

  • renovate[bot] (08 Jul 26)

    chore(deps): update danielroe/provenance-action digest to da28a90

  • renovate[bot] (08 Jul 26)

    chore(deps): update ghcr.io/techknowlogick/xgo:go-1.26.x docker digest to b00957d

Vikunja Security

Security Advisories (36)

  • medium Patched CVSS 4.3

    CVE-2026-40103 Scoped API tokens with projects.background permission can delete project backgrounds

  • high Patched CVSS 7.4

    CVE-2026-34727 TOTP Two-Factor Authentication Bypass via OIDC Login Path

  • medium Patched CVSS 4.1

    CVE-2026-35601 iCalendar Property Injection via CRLF in CalDAV Task Output

  • medium Patched CVSS 5.4

    CVE-2026-35600 HTML Injection via Task Titles in Overdue Email Notifications

  • medium Patched CVSS 6.5

    CVE-2026-35599 Algorithmic Complexity DoS in Repeating Task Handler

  • medium Patched CVSS 5.4

    CVE-2026-35602 File Size Limit Bypass via Vikunja Import

  • medium Patched CVSS 4.3

    CVE-2026-35598 Missing Authorization on CalDAV Task Read

  • medium Patched CVSS 5.9

    CVE-2026-35597 TOTP Brute-Force Due to Non-Functional Account Lockout

  • medium Patched CVSS 4.3

    CVE-2026-35596 Broken Access Control on Label Read via SQL Operator Precedence Bug

  • high Patched CVSS 8.3

    CVE-2026-35595 Privilege Escalation via Project Reparenting

  • medium Patched CVSS 6.5

    CVE-2026-35594 Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

  • medium Patched

    CVE-2026-33700 Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion

  • high Patched

    CVE-2026-33668 Disabled/Locked User Accounts Can Still Authenticate via API Tokens, CalDAV, and OpenID Connect

  • medium Patched CVSS 6.4

    CVE-2026-33679 SSRF via OpenID Connect Avatar Download Bypasses Webhook SSRF Protections

  • medium Patched CVSS 6.4

    CVE-2026-33675 SSRF via Todoist/Trello Migration File Attachment URLs Allows Reading Internal Network Resources

  • medium Patched CVSS 6.5

    CVE-2026-33676 Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read

  • medium Patched CVSS 6.5

    CVE-2026-33677 Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API

  • high Patched CVSS 8.1

    CVE-2026-33678 IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion

  • high Patched CVSS 7.5

    CVE-2026-33680 Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation

  • critical Patched CVSS 9.1

    GHSA-2pv8-4c52-mf8j Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

  • high Patched

    CVE-2026-33334 Any frontend XSS escalates to Remote Code Execution due to nodeIntegration in Vikunja Desktop

  • high Patched

    CVE-2026-33335 Arbitrary local application invocation via unvalidated shell.openExternal in Vikunja Desktop

  • critical Patched

    CVE-2026-33336 Remote Code Execution via same-window navigation in Vikunja Desktop

  • medium Patched

    CVE-2026-33313 IDOR in Task Comments Allows Reading Arbitrary Comments

  • medium Patched

    CVE-2026-33312 Read-only users can delete project background images via broken object-level authorization

  • medium Patched

    CVE-2026-33315 2FA Bypass via Caldav Basic Auth

  • high Patched CVSS 8.1

    CVE-2026-33316 Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement

  • medium Patched CVSS 5.7

    CVE-2026-33473 TOTP Reuse During Validity Window

  • high Patched

    CVE-2026-33474 DoS via Image Preview Generation

  • medium Patched CVSS 5.3

    CVE-2026-29794 Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers

  • critical Patched CVSS 9.8

    CVE-2026-28268 Account Takeover via Password Reset Token Reuse

  • high Patched CVSS 7.2

    CVE-2026-27819 Path Traversal in CLI Restore

  • critical Patched CVSS 9.1

    CVE-2026-27575 Weak Password Policy Combined with Persistent Sessions After Password Change

  • high Patched CVSS 7.3

    CVE-2026-27616 Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token Exposure

  • medium Patched CVSS 6.1

    CVE-2026-27116 Reflected HTML Injection via filter Parameter in Projects Module

  • high Patched

    CVE-2026-25935 XSS Via Task Preview

Vikunja Website

Website

Vikunja: The task manager you actually own

Vikunja is open-source task management you can self-host. Lists, Kanban, Gantt, and more — on your server or ours. Made and hosted in the EU.

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address 104.21.47.206
  • Location San Francisco, California, United States of America, NA
  • ISP CloudFlare Inc.
  • ASN AS13335

Associated Countries

  • US US
  • DE DE

Safety Score

Website marked as safe

100%

Blacklist Check

vikunja.io was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Vikunja Docker

Container Info

Vikunja

The to-do app to organize your life.| Before use create custom template and Edit: VIKUNJA_SERVICE_FRONTENDURL , VIKUNJA_API_URL & VIKUNJA_SERVICE_JWTSECRET

#Tools#Productivity

Run Command

docker run -d \
  -e PUID=${PUID} \
  -e PGID=${PGID} \
  -e PORT=${PORT} \
  

Compose File

version: 3.8
services:
  vikunja:
    environment:
      PUID: 1000
      PGID: 1000
      PORT: 

Environment Variables

  • Var Name Default
  • PUID 1000
  • PGID 1000
  • PORT null

Vikunja Reviews

More Cloud Productivity Suites

  • A zero knowledge cloud productivity suite. Provides Rich Text, Presentations, Spreadsheets, Kanban, Paint a code editor and file drive. All notes and user content, are encrypted by default, and can only be accessed with specific URL. The main disadvantage, is a lack of Android, iOS and desktop apps - CryptPad is entirely web-based. You can use their web service, or you can host your own instance. Price for hosted: free for 50mb or $5/ month for premium.

  • A platform providing online services based on principles of freedom, privacy, federation and decentralization. It is an implementation of NextCloud, with strong encryption configured - it is widely used by journalists, activists and whistle-blowers. It is free to use, but there have been reported reliability issues of the cloud services.

  • NextCloud

    NextCloud

    nextcloud.com

    A complete self-hosted productivity platform, with a strong community and growing app store. NextCloud is similar to (but arguably more complete than) Google Drive, Office 365 and Dropbox. Clear UI and stable native apps across all platforms, and also supports file sync. Supports encrypted files, but you need to configure this yourself. Fully open source.

  • An open source platform for self-hosting web apps. Once you've set it up, you can install items from the Sandstorm App Market with -click, similar to NextCloud in terms of flexibility.

About the Data: Vikunja

Change History

API

You can access Vikunja's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/vikunja

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Vikunja

Help your friends compare Cloud Productivity Suites, and pick privacy-respecting software and services.
Share Vikunja and Awesome Privacy with your network!

View Cloud Productivity Suites (5)