Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kimai

First CVE: Aug 23, 2019Active for: 7 yearsTotal CVEs: 20
18.0
VTI Score
Low

Kimai is a modestly represented time-tracking and project-management application that, despite its narrow product footprint, maintains sustained visibility in the vulnerability landscape through its deployment in business workflows. Its vulnerability profile centers on web-application input-handling and template-processing weaknesses, particularly cross-site scripting, cross-site request forgery, CSV formula injection, and template-engine exploitation, alongside instances of sensitive information exposure. A meaningful share of the vendor's disclosures reach serious severity, reflecting the access to user and project data that these flaws can enable in a system managing timekeeping and billing records. Defenders should treat this vendor's advisories as relevant to any internal or cloud-hosted time-tracking deployment and apply input-validation and output-encoding scrutiny to instances under their purview; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kimai over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2019
6 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-53957HIGH
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executin
Dec 19, 20258.830NONO
CVE-2020-19825CRITICAL
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
Feb 15, 20239.630NONO
CVE-2021-3985CRITICAL
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Dec 1, 20219.028NONO
CVE-2026-42267MEDIUM
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51))
May 8, 20265.725NONO
CVE-2021-43515HIGH
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistre
Apr 8, 20227.825NONO
CVE-2026-23626MEDIUM
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`Def
Jan 18, 20266.824NONO
CVE-2026-44298MEDIUM
Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoi
May 8, 20264.923NONO
CVE-2026-28685MEDIUM
Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify
Mar 6, 20266.523NONO
CVE-2021-4033MEDIUM
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Dec 9, 20216.523NONO
CVE-2021-3976MEDIUM
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Nov 19, 20216.523NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
70%
15%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None8 (40.0%)
Unknown0 (0.0%)
Required12 (60.0%)
Privileges Required
Low8 (40.0%)
High4 (20.0%)
None8 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kimai.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kimai — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kimai's Products

View all 5 CNAs →

Top CWEs