kimai/kimai vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52828Mediumkimai/kimai: Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD AccessCVE-2026-52827Highkimai/kimai: Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTPCVE-2026-52826Mediumkimai/kimai: Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate ManipulationCVE-2026-52825Mediumkimai/kimai: Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized…CVE-2026-52824Criticalkimai/kimai: Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account TakeoverCVE-2026-52823Mediumkimai/kimai: Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State ChangesCVE-2026-52822Mediumkimai/kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access RevocationCVE-2026-52821Mediumkimai/kimai: Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized ProjectsCVE-2026-52820Mediumkimai/kimai: Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypassCVE-2026-52819Mediumkimai/kimai: Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the…CVE-2026-49992Mediumkimai/kimai: Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure ChangesCVE-2026-49865Mediumkimai/kimai: Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLsGHSA-J5MC-P8QG-39J7Lowkimai/kimai: Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark ManipulationGHSA-M492-GV72-XVXJLowkimai/kimai: Kimai Password Reset Link Remains Valid After Password ChangeCVE-2026-44298Mediumkimai/kimai: Kimai has an arbitrary file read in its invoice PDF renderer (admin)GHSA-VRQV-52X7-RM4VMediumkimai/kimai: Kimai's Twig function config() leaks server-wide secrets (LDAP bind password, SAML SP private key) via invoice/export templatesGHSA-9G2Q-W3W2-VF7QMediumkimai/kimai: Kimai has Missing Voter Check that Allows Cross-Team Timesheet ManipulationCVE-2026-42267Mediumkimai/kimai: Kimai vulnerable to formula Injection via tag names in XLSX exportCVE-2026-41498Lowkimai/kimai: Kimai has Missing Object-Level Authorization in the Team APIGHSA-JRC6-FMHW-FPQ2Lowkimai/kimai: Kimai: Username enumeration via timing on X-AUTH-USERCVE-2026-40486Mediumkimai/kimai: Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rateCVE-2026-40479Mediumkimai/kimai: Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member WidgetGHSA-RH42-6RJ2-XWMCLowkimai/kimai: Kimai leaks API Token Hash via Invoice Twig TemplateGHSA-3JP4-MHH4-GCGRLowkimai/kimai: Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS HandlerCVE-2026-28685Mediumkimai/kimai: Kimai's API invoice endpoint missing customer-level access control (IDOR)

Stop the waste.
Protect your environment with Kodem.