Kimai

Kimai

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 21:29:34
  • Zuletzt bearbeitet 23.09.2026 18:22:16

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through ...

  • EPSS 0.33%
  • Veröffentlicht 11.09.2026 21:17:10
  • Zuletzt bearbeitet 23.09.2026 18:22:16

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered i...

  • EPSS 0.18%
  • Veröffentlicht 02.09.2026 11:11:20
  • Zuletzt bearbeitet 02.09.2026 14:17:17

Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activit...

  • EPSS 0.15%
  • Veröffentlicht 02.09.2026 11:11:19
  • Zuletzt bearbeitet 02.09.2026 13:54:48

Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or ...

  • EPSS 0.14%
  • Veröffentlicht 02.09.2026 11:11:19
  • Zuletzt bearbeitet 02.09.2026 16:17:33

Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can ex...

  • EPSS 0.21%
  • Veröffentlicht 02.09.2026 11:11:18
  • Zuletzt bearbeitet 02.09.2026 14:17:17

Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the cont...

  • EPSS 0.19%
  • Veröffentlicht 02.09.2026 11:11:17
  • Zuletzt bearbeitet 04.09.2026 03:17:45

Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activ...

  • EPSS 0.35%
  • Veröffentlicht 25.08.2026 23:19:07
  • Zuletzt bearbeitet 08.10.2026 16:17:46

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_ti...

  • EPSS 0.2%
  • Veröffentlicht 25.08.2026 23:19:06
  • Zuletzt bearbeitet 08.10.2026 16:17:46

Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice...

  • EPSS 0.25%
  • Veröffentlicht 25.08.2026 23:19:05
  • Zuletzt bearbeitet 08.10.2026 16:17:45

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs ...