Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.31%—KimaiAI26/8/202631/8/2026
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user,…
AplazadaAlta (8.7)0.47%—KimaiAI26/8/202631/8/2026
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization…
AnalizadaMedia (4.9)0.42%—Kimai8/5/202617/6/2026
Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice templates, which can call pdfContext.setOption('associated_files', ...) inside the sandboxed Twig…
AnalizadaMedia (5.4)0.33%—Kimai8/5/202617/6/2026
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a timesheet. When an admin exports timesheets to XLSX, ArrayFormatter.formatValue() joins tag names…
AnalizadaBaja (3.3)0.24%—Kimai8/5/202617/6/2026
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the edit_team…
AnalizadaMedia (4.3)0.33%—Kimai17/4/202617/6/2026
Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields are correctly marked…
AnalizadaMedia (5.4)0.25%—Kimai17/4/202617/6/2026
Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype and rendered through…
AnalizadaMedia (6.5)0.47%—Kimai6/3/202617/6/2026
Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify the requesting user has access to the invoice's customer. Any user with ROLE_TEAMLEAD (which grants view_invoice) can read all invoices in…
AnalizadaMedia (5.1)0.28%—Kimai11/2/202617/6/2026
Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.
AnalizadaMedia (6.8)0.45%—Kimai18/1/202617/6/2026
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`DefaultPolicy`) that allows arbitrary method calls on objects available in the template context. An authenticated user with export permissions…
AnalizadaAlta (8.5)0.59%—Kimai19/12/202517/6/2026
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
AplazadaCrítica (9.3)1.8%💥 ExploitKimaiAI31/7/202516/6/2026
An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental conditions. This can lead to remote code execution…
AnalizadaMedia (6.5)0.79%—Kimai7/5/202417/6/2026
A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Session Handler. The manipulation of the argument PHPSESSIONID leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather…
AnalizadaMedia (6.5)0.64%—Kimai28/3/202417/6/2026
Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams…
ModificadaAlta (7.2)1.5%—Kimai31/10/202317/6/2026
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and…
ModificadaCrítica (9.6)0.70%—Kimai15/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
ModificadaAlta (7.8)1.0%—Kimai8/4/202217/6/2026
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
ModificadaMedia (6.5)0.52%—Kimai 29/12/202117/6/2026
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (6.1)0.79%—Kimai2 Project Kimai21/12/202117/6/2026
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.5)1.1%—Kimai2 Project Kimai21/12/202117/6/2026
kimai2 is vulnerable to Improper Access Control
ModificadaCrítica (9)1.3%—Kimai21/12/202117/6/2026
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.3)0.40%—Kimai 219/11/202117/6/2026
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (4.3)0.38%—Kimai 219/11/202117/6/2026
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (6.5)0.40%—Kimai 219/11/202117/6/2026
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (6.1)0.86%—Kimai 223/8/201917/6/2026
Kimai v2 before 1.1 has XSS via a timesheet description.
Orbitaley — Vulnerabilidades