Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kimai — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting kimai. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kimai is an open-source time-tracking application designed for businesses to monitor employee working hours and project costs. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation flaws. The application's web interface has frequently contained input validation weaknesses allowing attackers to execute unauthorized commands or steal session data. While no major public incidents have been widely documented, the seven recorded CVEs highlight consistent security concerns in areas like authentication, access control, and data sanitization. Its modular architecture, while flexible, introduces potential attack surfaces through plugins and extensions that may not undergo rigorous security review.

Found 20 results / 20 Clear Filters
Top products by kimai: kimai
CVE ID Title CVSS Severity Published
CVE-2026-80202 Kimai before 2.56.0 Authorization Bypass via TimesheetVoter — kimai CWE-863 8.8 High 2026-08-25
CVE-2026-80201 Kimai before 2.53.0 API Token Leakage via Invoice Template — kimai CWE-94 2.0 Low 2026-08-25
CVE-2026-80200 Kimai before 2.53.0 Open Redirect via RelayState — kimai CWE-601 - - 2026-08-25
CVE-2026-80199 Kimai before 2.54.0 Username Enumeration via Timing Oracle — kimai CWE-208 3.7 Low 2026-08-25
CVE-2026-80198 Kimai before 2.56.0 Information Disclosure via config() Twig Function — kimai CWE-693 7.5 High 2026-08-25
CVE-2026-80197 Kimai before 2.57.0 Improper Authorization via Favorite Endpoints — kimai CWE-639 4.3 Medium 2026-08-25
CVE-2026-80196 Kimai before 2.58.0 Authentication Bypass via Password Reset Link — kimai CWE-640 7.5 High 2026-08-25
CVE-2026-80194 Kimai before 2.64.0 Missing Authorization via ProjectViewController export — kimai CWE-200 4.3 Medium 2026-08-25
CVE-2026-80195 Kimai before 2.63.0 Team Membership Removal via API — kimai CWE-841 5.4 Medium 2026-08-25
CVE-2026-80193 Kimai before 2.62.0 Authorization Bypass via QuickEntry — kimai CWE-862 8.8 High 2026-08-25
CVE-2026-44298 Kimai: Arbitrary file read in invoice PDF renderer (admin) — kimai CWE-22 4.1 Medium 2026-05-08
CVE-2026-41498 Kimai: Team API Missing Object-Level Authorization — kimai CWE-862 3.3 Low 2026-05-08
CVE-2026-42267 Kimai: Formula Injection via tag names in XLSX export — kimai CWE-1236 6.5AI Medium AI 2026-05-08
CVE-2026-40486 Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate — kimai CWE-915 4.3 Medium 2026-04-17
CVE-2026-40479 Kimai: Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget — kimai CWE-79 5.4 Medium 2026-04-17
CVE-2026-28685 Kimai: API invoice endpoint missing customer-level access control (IDOR) — kimai CWE-285 6.5 Medium 2026-03-06
CVE-2026-23626 Kimai Vulnerable to Authenticated Server-Side Template Injection (SSTI) — kimai CWE-1336 6.8 Medium 2026-01-18
CVE-2023-53957 Kimai 1.30.10 SameSite Cookie Vulnerability Session Hijacking — Kimai CWE-1275 9.8 Critical 2025-12-19
CVE-2024-29200 API returns timesheet entries a user should not be authorized to view — kimai CWE-1220 6.8 Medium 2024-03-28
CVE-2023-46245 Kimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig File — kimai CWE-1336 7.2 High 2023-10-31

This page lists every published CVE security advisory associated with kimai. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.