Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kimai — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting kimai. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kimai is an open-source time-tracking application designed for businesses to monitor employee working hours and project costs. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation flaws. The application's web interface has frequently contained input validation weaknesses allowing attackers to execute unauthorized commands or steal session data. While no major public incidents have been widely documented, the seven recorded CVEs highlight consistent security concerns in areas like authentication, access control, and data sanitization. Its modular architecture, while flexible, introduces potential attack surfaces through plugins and extensions that may not undergo rigorous security review.

Top products by kimai: kimai
CVE ID Title CVSS Severity Published
CVE-2026-52827 Kimai: Two-factor authentication bypass on the Kimai API — kimai CWE-287 7.1 High 2026-09-15
CVE-2026-52822 Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation — kimai CWE-285 5.3 Medium 2026-09-15
CVE-2026-52828 Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access — kimai CWE-862 5.3 Medium 2026-09-15
CVE-2026-52826 Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation — kimai CWE-285 5.3 Medium 2026-09-15
CVE-2026-52823 Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes — kimai CWE-352 5.3 Medium 2026-09-15
CVE-2026-52824 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover — kimai CWE-1188 9.1 Critical 2026-09-15
CVE-2026-52825 Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility — kimai CWE-285 5.3 Medium 2026-09-15
CVE-2026-52821 Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects — kimai CWE-639 5.3 Medium 2026-09-15
CVE-2026-52820 Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass — kimai CWE-639 5.3 Medium 2026-09-15
CVE-2026-52819 Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target — kimai CWE-863 6.3 Medium 2026-09-15
CVE-2026-49992 Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes — kimai CWE-352 6.3 Medium 2026-09-11
CVE-2026-49865 Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs — kimai CWE-918 5.3 Medium 2026-09-11
CVE-2026-84807 Kimai before 2.65.0 Authentication Bypass via Team Creation — kimai CWE-266 5.4 Medium 2026-09-02
CVE-2026-84808 Kimai before 2.65.0 Authorization Bypass via API Timesheet — kimai CWE-863 4.3 Medium 2026-09-02
CVE-2026-84806 Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints — kimai CWE-732 5.4 Medium 2026-09-02
CVE-2026-84805 Kimai 2.61.0 before 2.63.0 Authentication Bypass via API — kimai CWE-862 4.3 Medium 2026-09-02
CVE-2026-84804 Kimai before 2.65.0 Authorization Bypass via Team Activity API — kimai CWE-284 5.4 Medium 2026-09-02
CVE-2026-80202 Kimai before 2.56.0 Authorization Bypass via TimesheetVoter — kimai CWE-863 8.8 High 2026-08-25
CVE-2026-80200 Kimai before 2.53.0 Open Redirect via RelayState — kimai CWE-601 4.7 Medium 2026-08-25
CVE-2026-80201 Kimai before 2.53.0 API Token Leakage via Invoice Template — kimai CWE-94 2.0 Low 2026-08-25
CVE-2026-80199 Kimai before 2.54.0 Username Enumeration via Timing Oracle — kimai CWE-208 3.7 Low 2026-08-25
CVE-2026-80198 Kimai before 2.56.0 Information Disclosure via config() Twig Function — kimai CWE-693 7.5 High 2026-08-25
CVE-2026-80197 Kimai before 2.57.0 Improper Authorization via Favorite Endpoints — kimai CWE-639 4.3 Medium 2026-08-25
CVE-2026-80196 Kimai before 2.58.0 Authentication Bypass via Password Reset Link — kimai CWE-640 7.5 High 2026-08-25
CVE-2026-80195 Kimai before 2.63.0 Team Membership Removal via API — kimai CWE-841 5.4 Medium 2026-08-25
CVE-2026-80194 Kimai before 2.64.0 Missing Authorization via ProjectViewController export — kimai CWE-200 4.3 Medium 2026-08-25
CVE-2026-80193 Kimai before 2.62.0 Authorization Bypass via QuickEntry — kimai CWE-862 8.8 High 2026-08-25
CVE-2026-44298 Kimai: Arbitrary file read in invoice PDF renderer (admin) — kimai CWE-22 4.1 Medium 2026-05-08
CVE-2026-41498 Kimai: Team API Missing Object-Level Authorization — kimai CWE-862 3.3 Low 2026-05-08
CVE-2026-42267 Kimai: Formula Injection via tag names in XLSX export — kimai CWE-1236 6.5AI Medium AI 2026-05-08

This page lists every published CVE security advisory associated with kimai. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.