Critical severity9.0NVD Advisory· Published Dec 1, 2021· Updated Jun 17, 2026
CVE-2021-3985
CVE-2021-3985
Description
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kevinpapst/kimai2Packagist | < 1.16.3 | 1.16.3 |
Affected products
2- kevinpapst/kevinpapst/kimai2v5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/kevinpapst/kimai2/commit/76e09447c85e762882126b49626a4fe4d93fe8b5nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/89d6c3de-efbd-4354-8cc8-46e999e4c5a4nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-x68c-4gmm-5g43ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3985ghsaADVISORY
- github.com/kevinpapst/kimai2/releases/tag/1.16.3ghsaWEB
News mentions
0No linked articles in our index yet.