Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kimai MEDIUM 5.7
CVE-2026-42267

Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string…

Fix: 2.54.0+
Fix from $1,600 2026-05-08
Kimai MEDIUM 5.4
CVE-2026-40479

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape …

Fix: 2.53.0+
Fix from $1,600 2026-04-17
Kimai MEDIUM 6.5
CVE-2026-28685

Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice …

Fix: 2.51.0+
Fix from $1,600 2026-03-06
Kimai MEDIUM 5.4
CVE-2019-25317

Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attac…

Fix: after 1.1
Fix from $1,600 2026-02-11
Kimai MEDIUM 6.8
CVE-2026-23626

Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly p…

Fix: 2.46.0+
Fix from $1,600 2026-01-18
Kimai HIGH 8.8
CVE-2023-53957

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers …

No fix yet
Fix from $1,950 2025-12-19
Kimai MEDIUM 6.5
CVE-2024-4596

A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Fix: 2.16.0+
Fix from $1,600 2024-05-07
Kimai MEDIUM 6.5
CVE-2024-29200

Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, t…

Fix: 2.13.0+
Fix from $1,600 2024-03-28
Kimai HIGH 7.2
CVE-2023-46245

Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which ca…

Fix: after 2.10
Fix from $1,950 2023-10-31
Kimai CRITICAL 9.6
CVE-2020-19825

Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated p…

Patch available
Fix from $2,300 2023-02-15
Kimai HIGH 7.8
CVE-2021-43515

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malic…

Fix: 1.14.1+
Fix from $1,950 2022-04-08
Kimai 2 MEDIUM 6.5
CVE-2021-4033

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 1.16.7+
Fix from $1,600 2021-12-09
Kimai2 CRITICAL 9.0
CVE-2021-3985

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 1.16.3+
Fix from $2,300 2021-12-01
Kimai 2 MEDIUM 6.5
CVE-2021-3976

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 1.16.2+
Fix from $1,600 2021-11-19
Kimai 2 MEDIUM 6.1
CVE-2019-15481

Kimai v2 before 1.1 has XSS via a timesheet description.

Fix: 1.1+
Fix from $1,600 2019-08-23