kimai has 14 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 12. The median CVSS is 5.3 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (5) and CWE-639 (4). Most affected products: kimai (12), kimai/kimai (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 14 prev 0
Weakness classes
Products
- kimai 12
- kimai/kimai 2
Worst active — by depth score
CVE-2026-52824Critical· 9.1Kimai is an open-source time tracking application62CVE-2026-52819Medium· 6.3Kimai is an open-source time tracking application47CVE-2026-49865Medium· 5.3Kimai is an open-source time tracking application41CVE-2026-52827High· 7.1Kimai is an open-source time tracking application39CVE-2026-49992Medium· 6.3Kimai is an open-source time tracking application35
kimai vulnerabilities
CVEs affecting kimai, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-52827High· 7.1Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the…
CVE-2026-52828Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives b…
CVE-2026-52819Medium· 6.3PoCKimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a…
CVE-2026-52820Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQue…
CVE-2026-52821Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability…
CVE-2026-52822Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after…
CVE-2026-52823Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing o…
CVE-2026-52824Critical· 9.1PoCKimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that …
CVE-2026-52825Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the ref…
CVE-2026-52826Medium· 5.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the author…
CVE-2026-49992Medium· 6.3Kimai is an open-source time tracking application
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…
CVE-2026-49865Medium· 5.3PoCKimai is an open-source time tracking application
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…
GHSA-j5mc-p8qg-39j7LowKimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
GHSA-m492-gv72-xvxjLowKimai Password Reset Link Remains Valid After Password Change
Kimai Password Reset Link Remains Valid After Password Change