Kronos operates a focused portfolio of web-based time and attendance systems that manage workforce scheduling and payroll data for many organizations, concentrating the vendor's exposure in a high-value attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes—including cross-site scripting, SQL injection, XML external entity injection, and authorization bypasses—are characteristic of web applications handling sensitive employee and financial records. Defenders should prioritize patching Kronos Web Time & Attendance deployments, particularly internet-reachable instances; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kronos over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8495HIGH In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privi | Jan 30, 2020 | 7.5 | 34 | NO | YES |
CVE-2020-35604CRITICAL An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. | Dec 21, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-8493MEDIUM A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and P | Jan 30, 2020 | 4.8 | 25 | NO | YES |
CVE-2020-8494HIGH In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an attacker with Timekeeper, Master Timekeeper, | Jan 30, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-14982MEDIUM A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker wi | Jul 15, 2020 | 6.5 | 18 | NO | NO |
CVE-2020-8496MEDIUM In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /Applica | Jan 30, 2020 | 4.8 | 17 | NO | NO |
CVE-2008-6666MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.three | Apr 8, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kronos.
Media articles that mention a CVE ID that affects a product developed by Kronos — matched by CVE ID, not by vendor name.