← Back

Habitica

habitica

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Habitica
habitica

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Habitica
1Habitica
Jun 17, 2026
Dec 12, 2024
2.0 LOW· v4
6.1 MEDIUM· v3
N/A· v2
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrec...Show more
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability. Arbitrary javascript can be executed by the attacker in the context of the victim’s session. Version 5.28.5 contains a patch.Show less
1Habitica
1Habitica
Jun 17, 2026
Dec 12, 2024
5.0 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due...Show more
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.Show less
1Habitica
1Habitica
Jun 17, 2026
Dec 12, 2024
5.0 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS...Show more
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS vulnerabilities due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.Show less
1Habitica
1Habitica
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
5.8 MEDIUM· v2
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
1Habitica
1Habitica
Jun 17, 2026
Jun 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.