doist CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

doist vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to doist, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-63317 Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a task/comment. [email protected] 5.4 0.18% 2025-12-01 2025-12-04
CVE-2025-57292 Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata. [email protected] 6.1 0.22% 2025-09-26 2025-10-07
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence