Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kimai — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in kimai, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the product Kimai. It collects documented security weaknesses, including injection flaws, access control failures, and server-side issues, covering the product's history from its initial releases through the most recent disclosed incidents. Users can utilize this resource to track the vendor's advisory history, understand the specific weakness classes prevalent in time and project tracking applications, or look up the detailed vulnerability history for Kimai deployments. By centralizing data from multiple sources, this overview highlights recurring risk patterns and helps security professionals assess the overall stability and maintenance practices of the software over time. The entries reflect a range of severity levels, allowing readers to contextualize the impact of each disclosed flaw within the broader ecosystem of web-based productivity tools. This aggregation supports compliance audits, patch prioritization strategies, and technical due diligence for organizations relying on Kimai for resource management. The goal is to provide a factual, chronological record of security events without editorial commentary, focusing strictly on technical classifications and resolution status.

Vendor: kimai

CVE ID Title CVSS Severity Published
CVE-2026-52827 Kimai: Two-factor authentication bypass on the Kimai API CWE-287 7.1 High 2026-09-15
CVE-2026-52822 Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation CWE-285 5.3 Medium 2026-09-15
CVE-2026-52828 Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access CWE-862 5.3 Medium 2026-09-15
CVE-2026-52826 Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation CWE-285 5.3 Medium 2026-09-15
CVE-2026-52823 Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes CWE-352 5.3 Medium 2026-09-15
CVE-2026-52824 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover CWE-1188 9.1 Critical 2026-09-15
CVE-2026-52825 Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility CWE-285 5.3 Medium 2026-09-15
CVE-2026-52821 Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects CWE-639 5.3 Medium 2026-09-15
CVE-2026-52820 Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass CWE-639 5.3 Medium 2026-09-15
CVE-2026-52819 Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target CWE-863 6.3 Medium 2026-09-15
CVE-2026-49992 Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes CWE-352 6.3 Medium 2026-09-11
CVE-2026-49865 Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs CWE-918 5.3 Medium 2026-09-11
CVE-2026-84808 Kimai before 2.65.0 Authorization Bypass via API Timesheet CWE-863 4.3 Medium 2026-09-02
CVE-2026-84807 Kimai before 2.65.0 Authentication Bypass via Team Creation CWE-266 5.4 Medium 2026-09-02
CVE-2026-84806 Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints CWE-732 5.4 Medium 2026-09-02
CVE-2026-84804 Kimai before 2.65.0 Authorization Bypass via Team Activity API CWE-284 5.4 Medium 2026-09-02
CVE-2026-84805 Kimai 2.61.0 before 2.63.0 Authentication Bypass via API CWE-862 4.3 Medium 2026-09-02
CVE-2026-80202 Kimai before 2.56.0 Authorization Bypass via TimesheetVoter CWE-863 8.8 High 2026-08-25
CVE-2026-80200 Kimai before 2.53.0 Open Redirect via RelayState CWE-601 4.7 Medium 2026-08-25
CVE-2026-80201 Kimai before 2.53.0 API Token Leakage via Invoice Template CWE-94 2.0 Low 2026-08-25
CVE-2026-80199 Kimai before 2.54.0 Username Enumeration via Timing Oracle CWE-208 3.7 Low 2026-08-25
CVE-2026-80197 Kimai before 2.57.0 Improper Authorization via Favorite Endpoints CWE-639 4.3 Medium 2026-08-25
CVE-2026-80198 Kimai before 2.56.0 Information Disclosure via config() Twig Function CWE-693 7.5 High 2026-08-25
CVE-2026-80196 Kimai before 2.58.0 Authentication Bypass via Password Reset Link CWE-640 7.5 High 2026-08-25
CVE-2026-80195 Kimai before 2.63.0 Team Membership Removal via API CWE-841 5.4 Medium 2026-08-25
CVE-2026-80194 Kimai before 2.64.0 Missing Authorization via ProjectViewController export CWE-200 4.3 Medium 2026-08-25
CVE-2026-80193 Kimai before 2.62.0 Authorization Bypass via QuickEntry CWE-862 8.8 High 2026-08-25
CVE-2026-44298 Kimai: Arbitrary file read in invoice PDF renderer (admin) CWE-22 4.1 Medium 2026-05-08
CVE-2026-41498 Kimai: Team API Missing Object-Level Authorization CWE-862 3.3 Low 2026-05-08
CVE-2026-42267 Kimai: Formula Injection via tag names in XLSX export CWE-1236 6.5AI Medium AI 2026-05-08

All 40 known CVE vulnerabilities affecting kimai with full Chinese analysis, references, and POCs where available.