Releases1.25K
Frequency3 days 20 hours
Last Release
Stars13.9K
A habit tracker app which treats your goals like a Role Playing Game.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS vulnerabilities due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.

6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.

6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability. Arbitrary javascript can be executed by the attacker in the context of the victim’s session. Version 5.28.5 contains a patch.

5.8 MEDIUM

In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.

6.1 MEDIUM4.3 MEDIUM

In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.