{"schema_version":1,"title":"kimai/kimai (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 38 vulnerabilities in kimai/kimai (Packagist): 0 in the last 7 days and 21 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-52828, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/kimai-kimai","json_url":"https://junglewise.ai/threats/technologies/kimai-kimai.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/kimai-kimai","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":38,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":12,"last_90_days":21,"last_365_days":33},"latest":[{"cve":"CVE-2026-52828","cvss":4,"epss":0.0047,"slug":"cve-2026-52828-kimai-missing-authorization-check-in-exportcontroller-export","title":"Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExpor","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:10.147+00:00","url":"https://junglewise.ai/threats/cve-2026-52828-kimai-missing-authorization-check-in-exportcontroller-export"},{"cve":"CVE-2026-52827","cvss":4,"epss":0.0058,"slug":"cve-2026-52827-kimai-2fa-bypass-in-rest-api-via-session-cookie-replay","title":"Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before T","severity":"high","exploited":false,"published_at":"2026-09-15T11:17:09.993+00:00","url":"https://junglewise.ai/threats/cve-2026-52827-kimai-2fa-bypass-in-rest-api-via-session-cookie-replay"},{"cve":"CVE-2026-52826","cvss":4,"epss":0.0043,"slug":"cve-2026-52826-kimai-improper-authorization-in-rate-edit-endpoints","title":"Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/cu","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:09.837+00:00","url":"https://junglewise.ai/threats/cve-2026-52826-kimai-improper-authorization-in-rate-edit-endpoints"},{"cve":"CVE-2026-52825","cvss":4,"epss":0.0045,"slug":"cve-2026-52825-kimai-improper-authorization-in-team-assignment-apis","title":"Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activitie","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:09.687+00:00","url":"https://junglewise.ai/threats/cve-2026-52825-kimai-improper-authorization-in-team-assignment-apis"},{"cve":"CVE-2026-52824","cvss":4,"epss":0.0133,"slug":"cve-2026-52824-kimai-insecure-default-app-secret-in-docker-image","title":"Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_thi","severity":"critical","exploited":false,"published_at":"2026-09-15T11:17:09.543+00:00","url":"https://junglewise.ai/threats/cve-2026-52824-kimai-insecure-default-app-secret-in-docker-image"},{"cve":"CVE-2026-52823","cvss":4,"epss":0.003,"slug":"cve-2026-52823-kimai-csrf-in-timesheet-stop-and-restart-api-endpoints","title":"Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/t","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:09.4+00:00","url":"https://junglewise.ai/threats/cve-2026-52823-kimai-csrf-in-timesheet-stop-and-restart-api-endpoints"},{"cve":"CVE-2026-52822","cvss":4,"epss":0.0047,"slug":"cve-2026-52822-kimai-improper-authorization-in-timesheet-restart-and-duplicate","title":"Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:09.25+00:00","url":"https://junglewise.ai/threats/cve-2026-52822-kimai-improper-authorization-in-timesheet-restart-and-duplicate"},{"cve":"CVE-2026-52821","cvss":4,"epss":0.0043,"slug":"cve-2026-52821-kimai-improper-authorization-in-activity-and-project-creation","title":"Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admi","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:09.107+00:00","url":"https://junglewise.ai/threats/cve-2026-52821-kimai-improper-authorization-in-activity-and-project-creation"},{"cve":"CVE-2026-52820","cvss":4,"epss":0.0045,"slug":"cve-2026-52820-kimai-timesheet-authorization-bypass-in-project-assignment","title":"Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-contro","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:08.957+00:00","url":"https://junglewise.ai/threats/cve-2026-52820-kimai-timesheet-authorization-bypass-in-project-assignment"},{"cve":"CVE-2026-52819","cvss":4,"epss":0.005,"slug":"cve-2026-52819-kimai-authorization-bypass-in-get-api-timesheets-api","title":"Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target id","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:08.8+00:00","url":"https://junglewise.ai/threats/cve-2026-52819-kimai-authorization-bypass-in-get-api-timesheets-api"},{"cve":"CVE-2026-49992","cvss":4,"epss":0.0022,"slug":"cve-2026-49992-kimai-csrf-in-team-creation-endpoints","title":"Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their","severity":"medium","exploited":false,"published_at":"2026-09-11T22:16:37.673+00:00","url":"https://junglewise.ai/threats/cve-2026-49992-kimai-csrf-in-team-creation-endpoints"},{"cve":"CVE-2026-49865","cvss":4,"epss":0.0035,"slug":"cve-2026-49865-kimai-ssrf-in-invoice-pdf-rendering-via-markdown-image-urls","title":"Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their inv","severity":"medium","exploited":false,"published_at":"2026-09-11T21:17:10.783+00:00","url":"https://junglewise.ai/threats/cve-2026-49865-kimai-ssrf-in-invoice-pdf-rendering-via-markdown-image-urls"},{"cve":"CVE-2026-80202","cvss":8.8,"epss":0.0045,"slug":"cve-2026-80202-kimai-authorization-bypass-in-timesheet-voter","title":"Kimai authorization bypass in timesheet voter","severity":"high","exploited":false,"published_at":"2026-08-26T05:18:27.98+00:00","url":"https://junglewise.ai/threats/cve-2026-80202-kimai-authorization-bypass-in-timesheet-voter"},{"cve":"CVE-2026-80201","cvss":3.1,"epss":0.0026,"slug":"cve-2026-80201-kimai-twig-invoice-template-sandbox-escape-via-unblocked-user","title":"Kimai Twig invoice template sandbox escape via unblocked User methods","severity":"low","exploited":false,"published_at":"2026-08-26T05:18:27.83+00:00","url":"https://junglewise.ai/threats/cve-2026-80201-kimai-twig-invoice-template-sandbox-escape-via-unblocked-user"},{"cve":"CVE-2026-80200","cvss":4.7,"epss":0.0036,"slug":"cve-2026-80200-kimai-open-redirect-in-saml-authentication-handler","title":"Kimai open redirect in SAML authentication handler","severity":"medium","exploited":false,"published_at":"2026-08-26T05:18:27.68+00:00","url":"https://junglewise.ai/threats/cve-2026-80200-kimai-open-redirect-in-saml-authentication-handler"},{"cve":"CVE-2026-80199","cvss":3.7,"epss":0.0031,"slug":"cve-2026-80199-kimai-tokenauthenticator-username-enumeration-via-timing-oracle","title":"Kimai TokenAuthenticator username enumeration via timing oracle","severity":"low","exploited":false,"published_at":"2026-08-26T05:18:27.53+00:00","url":"https://junglewise.ai/threats/cve-2026-80199-kimai-tokenauthenticator-username-enumeration-via-timing-oracle"},{"cve":"CVE-2026-80198","cvss":7.5,"epss":0.0043,"slug":"cve-2026-80198-kimai-twig-config-function-information-disclosure-in-templates","title":"Kimai Twig config() function information disclosure in templates","severity":"high","exploited":false,"published_at":"2026-08-26T05:18:27.38+00:00","url":"https://junglewise.ai/threats/cve-2026-80198-kimai-twig-config-function-information-disclosure-in-templates"},{"cve":"CVE-2026-80197","cvss":4.3,"epss":0.0026,"slug":"cve-2026-80197-kimai-improper-authorization-in-favorite-timesheet-endpoints","title":"Kimai improper authorization in favorite timesheet endpoints","severity":"medium","exploited":false,"published_at":"2026-08-26T05:18:27.23+00:00","url":"https://junglewise.ai/threats/cve-2026-80197-kimai-improper-authorization-in-favorite-timesheet-endpoints"},{"cve":"CVE-2026-80196","cvss":7.5,"epss":0.0054,"slug":"cve-2026-80196-kimai-authentication-bypass-in-password-reset-link","title":"Kimai authentication bypass in password reset link","severity":"high","exploited":false,"published_at":"2026-08-26T05:18:27.083+00:00","url":"https://junglewise.ai/threats/cve-2026-80196-kimai-authentication-bypass-in-password-reset-link"},{"cvss":1.3,"slug":"kimai-idor-in-favorite-timesheet-add-and-remove-endpoints-8fcded99","title":"Kimai IDOR in favorite timesheet add and remove endpoints","severity":"low","exploited":false,"published_at":"2026-07-02T20:44:05+00:00","url":"https://junglewise.ai/threats/kimai-idor-in-favorite-timesheet-add-and-remove-endpoints-8fcded99"},{"cvss":1.2,"slug":"kimai-weak-password-recovery-mechanism-allows-link-reuse-after-reset-26d67757","title":"Kimai weak password recovery mechanism allows link reuse after reset","severity":"low","exploited":false,"published_at":"2026-07-01T19:49:24+00:00","url":"https://junglewise.ai/threats/kimai-weak-password-recovery-mechanism-allows-link-reuse-after-reset-26d67757"},{"cve":"CVE-2026-44298","cvss":3.1,"epss":0.0042,"slug":"cve-2026-44298-kimai-has-an-arbitrary-file-read-in-its-invoice-pdf-renderer","title":"Kimai has an arbitrary file read in its invoice PDF renderer (admin)","severity":"low","exploited":false,"published_at":"2026-05-08T22:22:36+00:00","url":"https://junglewise.ai/threats/cve-2026-44298-kimai-has-an-arbitrary-file-read-in-its-invoice-pdf-renderer"},{"cve":"CVE-2026-42267","cvss":5.7,"epss":0.0033,"slug":"cve-2026-42267-kimai-formula-injection-in-xlsx-export-via-tag-names","title":"Kimai formula injection in XLSX export via tag names","severity":"medium","exploited":false,"published_at":"2026-05-08T04:16:20.533+00:00","url":"https://junglewise.ai/threats/cve-2026-42267-kimai-formula-injection-in-xlsx-export-via-tag-names"},{"cve":"CVE-2026-41498","cvss":3.3,"epss":0.0024,"slug":"cve-2026-41498-kimai-has-missing-object-level-authorization-in-the-team-api","title":"Kimai missing object-level authorization in Team API","severity":"low","exploited":false,"published_at":"2026-05-08T04:16:14.617+00:00","url":"https://junglewise.ai/threats/cve-2026-41498-kimai-has-missing-object-level-authorization-in-the-team-api"},{"cvss":3.7,"slug":"kimai-username-enumeration-via-timing-in-tokenauthenticator-92c13533","title":"Kimai username enumeration via timing in TokenAuthenticator","severity":"low","exploited":false,"published_at":"2026-04-17T22:30:59+00:00","url":"https://junglewise.ai/threats/kimai-username-enumeration-via-timing-in-tokenauthenticator-92c13533"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":10},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":58,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"mantisbt/mantisbt (Packagist)","slug":"mantisbt-mantisbt","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/mantisbt-mantisbt"},{"name":"froxlor/froxlor (Packagist)","slug":"froxlor-froxlor","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/froxlor-froxlor"},{"name":"yeswiki/yeswiki (Packagist)","slug":"yeswiki-yeswiki","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/yeswiki-yeswiki"},{"name":"twig/twig (Packagist)","slug":"twig-twig","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/twig-twig"},{"name":"shopper/framework (Packagist)","slug":"shopper-framework","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/shopper-framework"}],"technology":{"hub":true,"name":"kimai/kimai (Packagist)","slug":"kimai-kimai","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://www.kimai.org/","repo_url":"https://github.com/kimai/kimai","description":"An open-source time-tracking application built with PHP and Symfony.","url":"https://junglewise.ai/threats/technologies/kimai-kimai"},"most_severe":[{"cve":"CVE-2026-52824","cvss":4,"epss":0.0133,"slug":"cve-2026-52824-kimai-insecure-default-app-secret-in-docker-image","title":"Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_thi","severity":"critical","exploited":false,"published_at":"2026-09-15T11:17:09.543+00:00","url":"https://junglewise.ai/threats/cve-2026-52824-kimai-insecure-default-app-secret-in-docker-image"},{"cve":"CVE-2026-80202","cvss":8.8,"epss":0.0045,"slug":"cve-2026-80202-kimai-authorization-bypass-in-timesheet-voter","title":"Kimai authorization bypass in timesheet voter","severity":"high","exploited":false,"published_at":"2026-08-26T05:18:27.98+00:00","url":"https://junglewise.ai/threats/cve-2026-80202-kimai-authorization-bypass-in-timesheet-voter"},{"cve":"CVE-2026-80196","cvss":7.5,"epss":0.0054,"slug":"cve-2026-80196-kimai-authentication-bypass-in-password-reset-link","title":"Kimai authentication bypass in password reset link","severity":"high","exploited":false,"published_at":"2026-08-26T05:18:27.083+00:00","url":"https://junglewise.ai/threats/cve-2026-80196-kimai-authentication-bypass-in-password-reset-link"},{"cve":"CVE-2026-80198","cvss":7.5,"epss":0.0043,"slug":"cve-2026-80198-kimai-twig-config-function-information-disclosure-in-templates","title":"Kimai Twig config() function information disclosure in templates","severity":"high","exploited":false,"published_at":"2026-08-26T05:18:27.38+00:00","url":"https://junglewise.ai/threats/cve-2026-80198-kimai-twig-config-function-information-disclosure-in-templates"},{"cve":"CVE-2026-52827","cvss":4,"epss":0.0058,"slug":"cve-2026-52827-kimai-2fa-bypass-in-rest-api-via-session-cookie-replay","title":"Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before T","severity":"high","exploited":false,"published_at":"2026-09-15T11:17:09.993+00:00","url":"https://junglewise.ai/threats/cve-2026-52827-kimai-2fa-bypass-in-rest-api-via-session-cookie-replay"},{"cve":"CVE-2026-28685","cvss":6.5,"epss":0.0045,"slug":"cve-2026-28685-kimai-missing-authorization-in-api-invoice-endpoint","title":"Kimai missing authorization in API invoice endpoint","severity":"medium","exploited":false,"published_at":"2026-03-04T20:43:17+00:00","url":"https://junglewise.ai/threats/cve-2026-28685-kimai-missing-authorization-in-api-invoice-endpoint"},{"cve":"CVE-2026-42267","cvss":5.7,"epss":0.0033,"slug":"cve-2026-42267-kimai-formula-injection-in-xlsx-export-via-tag-names","title":"Kimai formula injection in XLSX export via tag names","severity":"medium","exploited":false,"published_at":"2026-05-08T04:16:20.533+00:00","url":"https://junglewise.ai/threats/cve-2026-42267-kimai-formula-injection-in-xlsx-export-via-tag-names"},{"cve":"CVE-2026-40479","cvss":5.4,"epss":0.0025,"slug":"cve-2026-40479-kimai-has-stored-xss-via-incomplete-html-attribute-escaping-in","title":"Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget","severity":"medium","exploited":false,"published_at":"2026-04-15T19:46:35+00:00","url":"https://junglewise.ai/threats/cve-2026-40479-kimai-has-stored-xss-via-incomplete-html-attribute-escaping-in"},{"cve":"CVE-2026-80200","cvss":4.7,"epss":0.0036,"slug":"cve-2026-80200-kimai-open-redirect-in-saml-authentication-handler","title":"Kimai open redirect in SAML authentication handler","severity":"medium","exploited":false,"published_at":"2026-08-26T05:18:27.68+00:00","url":"https://junglewise.ai/threats/cve-2026-80200-kimai-open-redirect-in-saml-authentication-handler"},{"cve":"CVE-2026-40486","cvss":4.3,"epss":0.0033,"slug":"cve-2026-40486-kimai-s-user-preferences-api-allows-standard-users-to-modify","title":"Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate","severity":"medium","exploited":false,"published_at":"2026-04-15T19:46:45+00:00","url":"https://junglewise.ai/threats/cve-2026-40486-kimai-s-user-preferences-api-allows-standard-users-to-modify"}],"generated_at":"2026-09-26T20:07:00.238639+00:00"}