Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.7
CVE-2026-42267
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string…
Kimai
2.54.0+
MEDIUM 5.4
CVE-2026-40479
Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape …
Kimai
2.53.0+
MEDIUM 6.5
CVE-2026-28685
Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice …
Kimai
2.51.0+
MEDIUM 5.4
CVE-2019-25317
Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attac…
Kimai
after 1.1
MEDIUM 6.8
CVE-2026-23626
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly p…
Kimai
2.46.0+
HIGH 8.8
CVE-2023-53957
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers …
Kimai
No fix yet
MEDIUM 6.5
CVE-2024-4596
A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component …
Kimai
2.16.0+
MEDIUM 6.5
CVE-2024-29200
Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, t…
Kimai
2.13.0+
HIGH 7.2
CVE-2023-46245
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which ca…
Kimai
after 2.10
CRITICAL 9.6
CVE-2020-19825
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated p…
Kimai
Patch available
HIGH 7.8
CVE-2021-43515
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malic…
Kimai
1.14.1+
MEDIUM 6.5
CVE-2021-4033
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Kimai 2
1.16.7+
CRITICAL 9.0
CVE-2021-3985
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Kimai2
1.16.3+
MEDIUM 6.5
CVE-2021-3976
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Kimai 2
1.16.2+
MEDIUM 6.1
CVE-2019-15481
Kimai v2 before 1.1 has XSS via a timesheet description.
Kimai 2
1.1+