Vulnerabilities in Kimai
37 resultsVexday analysis
Kimai apresenta footprint reduzido de segurança com apenas 1 CVE registrado na base, sem evidências de exploração ativa (KEV) ou vulnerabilidades críticas. A fraqueza identificada (CWE-1275 - Improper Initialization) não representa risco imediato, e a ausência de divulgações recentes indica estabilidade relativa no perfil de vulnerabilidades do fornecedor.
CVE-2023-46245HIGHKimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig FileEPSS 1.5%CVE-2026-52824CRITICALKimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account TakeoverEPSS 1.3%CVE-2024-29200MEDIUMAPI returns timesheet entries a user should not be authorized to viewEPSS 0.6%CVE-2023-53957HIGHKimai 1.30.10 SameSite Cookie Vulnerability Session HijackingEPSS 0.6%CVE-2026-52827HIGHKimai: Two-factor authentication bypass on the Kimai APIEPSS 0.6%CVE-2026-80196HIGHKimai before 2.58.0 Authentication Bypass via Password Reset LinkEPSS 0.5%CVE-2026-52819MEDIUMKimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the targetEPSS 0.5%CVE-2026-80193HIGHKimai before 2.62.0 Authorization Bypass via QuickEntryEPSS 0.5%CVE-2026-52822MEDIUMKimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access RevocationEPSS 0.5%CVE-2026-52828MEDIUMKimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD AccessEPSS 0.5%CVE-2026-23626MEDIUMKimai Vulnerable to Authenticated Server-Side Template Injection (SSTI)EPSS 0.5%CVE-2026-28685MEDIUMKimai: API invoice endpoint missing customer-level access control (IDOR)EPSS 0.5%CVE-2026-52825MEDIUMKimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized VisibilityEPSS 0.4%CVE-2026-52820MEDIUMKimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypassEPSS 0.4%CVE-2026-80202CRITICALKimai before 2.56.0 Authorization Bypass via TimesheetVoterEPSS 0.4%CVE-2026-80198HIGHKimai before 2.56.0 Information Disclosure via config() Twig FunctionEPSS 0.4%CVE-2026-52821MEDIUMKimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized ProjectsEPSS 0.4%CVE-2026-52826MEDIUMKimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate ManipulationEPSS 0.4%CVE-2026-44298MEDIUMKimai: Arbitrary file read in invoice PDF renderer (admin)EPSS 0.4%CVE-2026-80200MEDIUMKimai before 2.53.0 Open Redirect via RelayStateEPSS 0.4%