CVEs we hold for Kimai
Records whose assigning authority named Kimai as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-84808Kimai before 2.65.0 Authorization Bypass via API Timesheetkimai CVE-2026-84807Kimai before 2.65.0 Authentication Bypass via Team Creationkimai CVE-2026-84806Kimai before 2.63.0 Authorization Bypass via Team Access Endpointskimai CVE-2026-84805Kimai 2.61.0 before 2.63.0 Authentication Bypass via APIkimai CVE-2026-84804Kimai before 2.65.0 Authorization Bypass via Team Activity APIkimai CVE-2026-80202Kimai before 2.56.0 Authorization Bypass via TimesheetVoterkimai CVE-2026-80201Kimai before 2.53.0 API Token Leakage via Invoice Templatekimai CVE-2026-80199Kimai before 2.54.0 Username Enumeration via Timing Oraclekimai CVE-2026-80198Kimai before 2.56.0 Information Disclosure via config() Twig Functionkimai CVE-2026-80197Kimai before 2.57.0 Improper Authorization via Favorite Endpointskimai CVE-2026-80196Kimai before 2.58.0 Authentication Bypass via Password Reset Linkkimai CVE-2026-80195Kimai before 2.63.0 Team Membership Removal via APIkimai CVE-2026-80194Kimai before 2.64.0 Missing Authorization via ProjectViewController exportkimai CVE-2026-80193Kimai before 2.62.0 Authorization Bypass via QuickEntrykimai CVE-2026-52828Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Accesskimai CVE-2026-52827Kimai: Two-factor authentication bypass on the Kimai APIkimai CVE-2026-52826Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate…kimai CVE-2026-52825Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope…kimai CVE-2026-52824Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeoverkimai CVE-2026-52823Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changeskimai CVE-2026-52822Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access…kimai CVE-2026-52821Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projectskimai CVE-2026-52820Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypasskimai CVE-2026-52819Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being…kimai CVE-2026-49992Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changeskimai CVE-2026-49865Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLskimai CVE-2026-44298Kimai: Arbitrary file read in invoice PDF renderer (admin)kimai CVE-2026-42267Kimai: Formula Injection via tag names in XLSX exportkimai CVE-2026-40486Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_ratekimai CVE-2026-40479Kimai: Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widgetkimai CVE-2026-28685Kimai: API invoice endpoint missing customer-level access control (IDOR)kimai CVE-2026-23626Kimai Vulnerable to Authenticated Server-Side Template Injection (SSTI)kimai CVE-2024-29200API returns timesheet entries a user should not be authorized to viewkimai CVE-2023-53957Kimai 1.30.10 SameSite Cookie Vulnerability Session HijackingKimai CVE-2023-46245Kimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig Filekimai 39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.