Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.7 CVE-2026-42267 Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string… Kimai 2.54.0+ Fix from $1,6002026-05-08 MEDIUM 5.4 CVE-2026-40479 Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape … Kimai 2.53.0+ Fix from $1,6002026-04-17 MEDIUM 6.5 CVE-2026-28685 Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice … Kimai 2.51.0+ Fix from $1,6002026-03-06 MEDIUM 5.4 CVE-2019-25317 Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attac… Kimai after 1.1 Fix from $1,6002026-02-11 MEDIUM 6.8 CVE-2026-23626 Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly p… Kimai 2.46.0+ Fix from $1,6002026-01-18 HIGH 8.8 CVE-2023-53957 Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers … Kimai No fix yet Fix from $1,9502025-12-19 MEDIUM 6.5 CVE-2024-4596 A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component … Kimai 2.16.0+ Fix from $1,6002024-05-07 MEDIUM 6.5 CVE-2024-29200 Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, t… Kimai 2.13.0+ Fix from $1,6002024-03-28 HIGH 7.2 CVE-2023-46245 Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which ca… Kimai after 2.10 Fix from $1,9502023-10-31 CRITICAL 9.6 CVE-2020-19825 Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated p… Kimai Patch available Fix from $2,3002023-02-15 HIGH 7.8 CVE-2021-43515 CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malic… Kimai 1.14.1+ Fix from $1,9502022-04-08 MEDIUM 6.5 CVE-2021-4033 kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) Kimai 2 1.16.7+ Fix from $1,6002021-12-09 CRITICAL 9.0 CVE-2021-3985 kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Kimai2 1.16.3+ Fix from $2,3002021-12-01 MEDIUM 6.5 CVE-2021-3976 kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) Kimai 2 1.16.2+ Fix from $1,6002021-11-19 MEDIUM 6.1 CVE-2019-15481 Kimai v2 before 1.1 has XSS via a timesheet description. Kimai 2 1.1+ Fix from $1,6002019-08-23