Known Vulnerabilities for Kimai by Kimai
Listed below are 8 of the newest known vulnerabilities associated with "Kimai" by "Kimai".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84808 json | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84807 json | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creat... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84806 json | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84805 json | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the ... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84804 json | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers v... | Not Provided | 2026-09-02 | 2026-09-04 |
| CVE-2026-80202 json | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-80201 json | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getAp... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-80200 json | Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidat... | Not Provided | 2026-08-26 | 2026-08-28 |
| CVE-2026-80199 json | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enu... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-80198 json | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing ... | Not Provided | 2026-08-26 | 2026-08-28 |