Kimai
Kimai: vulnerabilidades y CVE
Kimai tiene 42 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE42
Últimos 12 meses36
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-52828 | Media (5.3) | 0.46% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which… |
| CVE-2026-52827 | Alta (7.1) | 0.58% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because… |
| CVE-2026-52826 | Media (5.3) | 0.43% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently… |
| CVE-2026-52825 | Media (5.3) | 0.45% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify… |
| CVE-2026-52824 | Crítica (9.1) | 1.3% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces… |
| CVE-2026-52823 | Media (5.3) | 0.30% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and… |
| CVE-2026-52822 | Media (5.3) | 0.46% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned… |
| CVE-2026-52821 | Media (5.3) | 0.43% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or… |
| CVE-2026-52820 | Media (5.3) | 0.45% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and… |
| CVE-2026-52819 | Media (6.3) | 0.50% | — | 15 sept 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply… |
| CVE-2026-49992 | Media (6.3) | 0.22% | — | 11 sept 2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These… |
| CVE-2026-49865 | Media (5.3) | 0.35% | — | 11 sept 2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown… |
| CVE-2026-84808 | Media (5.3) | 0.30% | — | 2 sept 2026 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission… |
| CVE-2026-84807 | Media (5.3) | 0.25% | — | 2 sept 2026 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create… |
| CVE-2026-84806 | Media (5.3) | 0.24% | — | 2 sept 2026 | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects,… |
| CVE-2026-84805 | Media (5.3) | 0.29% | — | 2 sept 2026 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these… |
| CVE-2026-84804 | Media (5.3) | 0.33% | — | 2 sept 2026 | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without… |
| CVE-2026-80202 | Crítica (9.3) | 0.45% | — | 26 ago 2026 | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD… |
| CVE-2026-80201 | Baja (2) | 0.26% | — | 26 ago 2026 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can… |
| CVE-2026-80200 | Media (5.3) | 0.36% | — | 26 ago 2026 | Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply… |
| CVE-2026-80199 | Media (6.3) | 0.31% | — | 26 ago 2026 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences… |
| CVE-2026-80198 | Alta (8.7) | 0.43% | — | 26 ago 2026 | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can… |
| CVE-2026-80197 | Alta (8.7) | 0.26% | — | 26 ago 2026 | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove… |
| CVE-2026-80196 | Alta (8.7) | 0.53% | — | 26 ago 2026 | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash.… |
| CVE-2026-80195 | Alta (8.7) | 0.36% | — | 26 ago 2026 | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted… |
| CVE-2026-80194 | Alta (8.7) | 0.31% | — | 26 ago 2026 | Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than… |
| CVE-2026-80193 | Alta (8.7) | 0.47% | — | 26 ago 2026 | Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can… |
| CVE-2026-44298 | Media (4.9) | 0.42% | — | 8 may 2026 | Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice… |
| CVE-2026-42267 | Media (5.4) | 0.33% | — | 8 may 2026 | Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a… |
| CVE-2026-41498 | Baja (3.3) | 0.24% | — | 8 may 2026 | Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.