Kimai is a modestly represented time-tracking and project-management application that, despite its narrow product footprint, maintains sustained visibility in the vulnerability landscape through its deployment in business workflows. Its vulnerability profile centers on web-application input-handling and template-processing weaknesses, particularly cross-site scripting, cross-site request forgery, CSV formula injection, and template-engine exploitation, alongside instances of sensitive information exposure. A meaningful share of the vendor's disclosures reach serious severity, reflecting the access to user and project data that these flaws can enable in a system managing timekeeping and billing records. Defenders should treat this vendor's advisories as relevant to any internal or cloud-hosted time-tracking deployment and apply input-validation and output-encoding scrutiny to instances under their purview; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kimai over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53957HIGH Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executin | Dec 19, 2025 | 8.8 | 30 | NO | NO |
CVE-2020-19825CRITICAL Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges. | Feb 15, 2023 | 9.6 | 30 | NO | NO |
CVE-2021-3985CRITICAL kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Dec 1, 2021 | 9.0 | 28 | NO | NO |
CVE-2026-42267MEDIUM Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) | May 8, 2026 | 5.7 | 25 | NO | NO |
CVE-2021-43515HIGH CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistre | Apr 8, 2022 | 7.8 | 25 | NO | NO |
CVE-2026-23626MEDIUM Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`Def | Jan 18, 2026 | 6.8 | 24 | NO | NO |
CVE-2026-44298MEDIUM Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoi | May 8, 2026 | 4.9 | 23 | NO | NO |
CVE-2026-28685MEDIUM Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify | Mar 6, 2026 | 6.5 | 23 | NO | NO |
CVE-2021-4033MEDIUM kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) | Dec 9, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-3976MEDIUM kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) | Nov 19, 2021 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kimai.
Media articles that mention a CVE ID that affects a product developed by Kimai — matched by CVE ID, not by vendor name.