Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-52827
  • github.com/kimai/kimai
Kimai: Two-factor authentication bypass on the Kimai API 15 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-52822
  • github.com/kimai/kimai
Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52828
  • github.com/kimai/kimai
Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52826
  • github.com/kimai/kimai
Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52823
  • github.com/kimai/kimai
Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52824
  • github.com/kimai/kimai
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover 15 Sep
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-52825
  • github.com/kimai/kimai
Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52821
  • github.com/kimai/kimai
Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52820
  • github.com/kimai/kimai
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-52819
  • github.com/kimai/kimai
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target 15 Sep
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-49992
  • github.com/kimai/kimai
Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes 11 Sep
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-49865
  • github.com/kimai/kimai
Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs 11 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-84808
  • github.com/kimai/kimai
Kimai before 2.65.0 Authorization Bypass via API Timesheet 02 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-84807
  • github.com/kimai/kimai
Kimai before 2.65.0 Authentication Bypass via Team Creation 02 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-84806
  • github.com/kimai/kimai
Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints 02 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-84805
  • github.com/kimai/kimai
Kimai 2.61.0 before 2.63.0 Authentication Bypass via API 02 Sep
  • Fix available
  • Severity - 5.3 (Medium)