Kromit
Kromit Titra: vulnerabilidades y CVE
Kromit Titra tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42092 | Media (6.5) | 0.37% | — | 4 may 2026 | titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and… |
| CVE-2026-21695 | Media (4.3) | 0.28% | — | 8 ene 2026 | Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authenticated users to inject arbitrary fields into time entries, bypassing… |
| CVE-2026-21694 | Alta (8.1) | 0.28% | — | 8 ene 2026 | Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted… |
| CVE-2025-69288 | Crítica (9.1) | 0.85% | — | 31 dic 2025 | Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute… |
| CVE-2022-2595 | Crítica (10) | 1.3% | — | 1 ago 2022 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. |
| CVE-2022-2098 | Crítica (9.8) | 1.0% | — | 16 jun 2022 | Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. |
| CVE-2022-2029 | Media (5.4) | 0.71% | — | 9 jun 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2028 | Media (5.4) | 0.71% | — | 9 jun 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2027 | Alta (8) | 1.2% | — | 9 jun 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2026 | Media (5.4) | 0.71% | — | 9 jun 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. |