VYPR

Vendor CVEs

Kimai

All CVEs

48 total · sorted by risk
  • CVE-2023-53957CriDec 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling…

  • CVE-2013-10033CriJul 31, 2025
    risk 0.64cvss —epss 0.02

    An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental…

  • CVE-2026-52824CriSep 15, 2026
    risk 0.52cvss —epss 0.02

    Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as…

  • CVE-2021-3985CriDec 1, 2021
    risk 0.52cvss 9.0epss 0.01

    kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-80202HigAug 26, 2026
    risk 0.50cvss 8.8epss 0.00

    Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet…

  • CVE-2026-80193HigAug 26, 2026
    risk 0.50cvss 8.8epss 0.00

    Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the…

  • CVE-2021-43515HigApr 8, 2022
    risk 0.44cvss 7.8epss 0.01

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.

  • CVE-2026-80198HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets…

  • CVE-2026-80196HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up…

  • CVE-2023-46245HigOct 31, 2023
    risk 0.40cvss 7.2epss 0.01

    Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig…

  • CVE-2026-52827HigSep 15, 2026
    risk 0.39cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and…

  • CVE-2026-42267MedMay 8, 2026
    risk 0.37cvss 5.7epss 0.00

    Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a timesheet. When an admin exports timesheets to XLSX,…

  • CVE-2026-23626MedJan 18, 2026
    risk 0.37cvss 6.8epss 0.00

    Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`DefaultPolicy`) that allows arbitrary method calls on objects available in the template context. An…

  • CVE-2024-29200MedMar 28, 2024
    risk 0.37cvss 6.8epss 0.01

    Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users…

  • CVE-2026-28685MedMar 6, 2026
    risk 0.35cvss 6.5epss 0.00

    Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify the requesting user has access to the invoice's customer. Any user with ROLE_TEAMLEAD (which grants…

  • CVE-2019-25317MedFeb 11, 2026
    risk 0.35cvss 6.4epss 0.00

    Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed…

  • CVE-2021-4033MedDec 9, 2021
    risk 0.35cvss 6.5epss 0.01

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3976MedNov 19, 2021
    risk 0.35cvss 6.5epss 0.00

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2026-52819MedSep 15, 2026
    risk 0.34cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team…

  • CVE-2026-49992MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly…

  • CVE-2026-84807MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches…

  • CVE-2026-84806MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can exploit insufficient permission…

  • CVE-2026-84804MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing…

  • CVE-2026-80195MedAug 26, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other…

  • CVE-2026-40479MedApr 17, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team…

  • CVE-2026-52828MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the…

  • CVE-2026-52826MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the…

  • CVE-2026-52825MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the…

  • CVE-2026-52823MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations through GET requests without a…

  • CVE-2026-52822MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or…

  • CVE-2026-52821MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the…

  • CVE-2026-52820MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQueryBuilderForFormType() places that…

  • CVE-2026-49865MedSep 11, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as…

  • CVE-2026-80200MedAug 26, 2026
    risk 0.24cvss 4.7epss 0.00

    Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users…

  • CVE-2026-84808MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they…

  • CVE-2026-84805MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin…

  • CVE-2026-80197MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by…

  • CVE-2026-80194MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no…

  • CVE-2026-40486MedApr 17, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and…

  • CVE-2021-3963MedNov 19, 2021
    risk 0.21cvss 4.3epss 0.00

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3957MedNov 19, 2021
    risk 0.21cvss 4.3epss 0.00

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2026-44298MedMay 8, 2026
    risk 0.20cvss 4.1epss 0.00

    Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice templates, which can call pdfContext.setOption('associated_files'…

  • CVE-2026-80199LowAug 26, 2026
    risk 0.17cvss 3.7epss 0.00

    Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users,…

  • CVE-2024-4596LowMay 7, 2024
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Session Handler. The manipulation of the argument PHPSESSIONID leads to information disclosure. The attack may be launched…

  • CVE-2026-41498LowMay 8, 2026
    risk 0.14cvss 3.3epss 0.00

    Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team…

  • CVE-2026-80201LowAug 26, 2026
    risk 0.06cvss 2.0epss 0.00

    Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API…

  • CVE-2020-19825CriFeb 15, 2023
    risk 0.00cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.

  • CVE-2019-15481MedAug 23, 2019
    risk 0.00cvss 6.1epss 0.01

    Kimai v2 before 1.1 has XSS via a timesheet description.