CVE-2026-80200
- EPSS 0.31%
- Veröffentlicht 25.08.2026 23:19:05
- Zuletzt bearbeitet 08.10.2026 16:17:45
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to r...
CVE-2026-80198
- EPSS 0.34%
- Veröffentlicht 25.08.2026 23:19:04
- Zuletzt bearbeitet 08.10.2026 16:17:45
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfi...
CVE-2026-80197
- EPSS 0.21%
- Veröffentlicht 25.08.2026 23:19:03
- Zuletzt bearbeitet 08.10.2026 16:17:45
Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another u...
CVE-2026-80196
- EPSS 0.42%
- Veröffentlicht 25.08.2026 23:19:03
- Zuletzt bearbeitet 08.10.2026 16:17:45
Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a pass...
CVE-2026-80195
- EPSS 0.28%
- Veröffentlicht 25.08.2026 23:19:02
- Zuletzt bearbeitet 03.09.2026 05:15:12
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenti...
CVE-2026-80194
- EPSS 0.24%
- Veröffentlicht 25.08.2026 23:19:01
- Zuletzt bearbeitet 31.08.2026 20:52:56
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the exp...
CVE-2026-80193
- EPSS 0.36%
- Veröffentlicht 25.08.2026 23:19:01
- Zuletzt bearbeitet 31.08.2026 20:52:56
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for tea...
CVE-2026-44298
- EPSS 0.28%
- Veröffentlicht 08.05.2026 03:32:06
- Zuletzt bearbeitet 08.05.2026 20:01:41
Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice templates, which can call pdfContex...
CVE-2026-41498
- EPSS 0.25%
- Veröffentlicht 08.05.2026 03:30:32
- Zuletzt bearbeitet 12.05.2026 13:59:03
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level owne...
CVE-2026-42267
- EPSS 0.22%
- Veröffentlicht 08.05.2026 03:28:52
- Zuletzt bearbeitet 13.05.2026 17:58:49
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a timesheet. When an admin export...