📦 Kimai

by Kimai

🔍 What is Kimai?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-53957

CRITICAL CVSS 9.8 Dec 19, 2025

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through crafted PHP scripts. This enables session hijacking where attackers can impersonate l...

CVE-2021-43515

HIGH CVSS 7.8 Apr 8, 2022

CVE-2021-43515 is a CSV injection vulnerability in Kimai time tracking software that allows attackers to inject malicious formulas into exported CSV files. When users open these files in spreadsheet a...

CVE-2019-25317

MEDIUM CVSS 6.4 Feb 11, 2026

Kimai 2 contains a persistent cross-site scripting (XSS) vulnerability that allows attackers to inject malicious SVG scripts into timesheet descriptions. When other users view these manipulated timesh...

CVE-2026-23626

MEDIUM CVSS 6.8 Jan 18, 2026

This vulnerability allows authenticated users with export permissions in Kimai time-tracking software to deploy malicious Twig templates that bypass security sandboxing. Attackers can extract sensitiv...