In Kimai versions prior to 2.58.0 a medium severity vulnerability CVE-2026-52823 was detected. This vulnerability allows an attacker to perform unauthorized actions by tricking an authenticated user into visiting a malicious link. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52823.
Read more Project ManagementIn Kimai versions 2.65.0 and earlier a medium severity vulnerability CVE-2026-84804 was detected. This vulnerability allows authenticated users to bypass authorization controls. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84804.
Read more Project ManagementIn Kimai versions from 2.61.0 before 2.63.0 a medium severity vulnerability CVE-2026-84805 was detected. This vulnerability allows an authenticated regular user to use the API to modify their own admin-only work-contract data. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84805.
Read more Project ManagementIn Kimai versions 2.52.0 and below a high severity vulnerability CVE-2026-40486 was detected. This vulnerability allows attackers with standard user accounts to modify restricted attributes such as hourly_rate and internal_rate via the User Preferences API, bypassing intended permission checks. This unauthorized financial tampering directly impacts invoice generation and timesheet calculations. To address this issue users must upgrade to version 2.53.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-40486.
Read more Project ManagementIn Kanboard versions prior to 1.2.51 a high severity vulnerability CVE-2026-29056 was detected. This vulnerability allows an attacker who receives a user invite link to inject `role=app-admin` during registration, creating an administrator account and escalating privileges. To address this issue, users should upgrade Kanboard to version 1.2.51. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-29056.
Read more Project ManagementIn Kanboard versions prior to 1.2.51 a high severity vulnerability CVE-2026-33058 was detected. This vulnerability allows attackers with permission to add users to a project to perform SQL injection and dump the entire Kanboard database. To address this issue, users should upgrade Kanboard to version 1.2.51. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33058.
Read more Project ManagementIn Kimai versions prior to 2.51.0 a medium severity vulnerability CVE-2026-28685 was detected. This vulnerability allows attackers with ROLE_TEAMLEAD to access invoices belonging to customers they should not have permission to view due to missing customer-level access control in the API. To address this issue, users should upgrade Kimai to version 2.51.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28685.
Read more Project ManagementIn Kanboard versions prior to 1.2.50 a medium severity vulnerability CVE-2026-25531 was identified. This vulnerability allows an authenticated user to duplicate tasks into projects they do not have access to because the TaskCreationController::duplicateProjects() endpoint does not properly validate user permissions for target projects. To address this issue, users should upgrade Kanboard to version 1.2.50. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25531.
Read more Project ManagementIn Kanboard versions prior to 1.2.50 a medium severity vulnerability CVE-2026-25530 was detected. This vulnerability allows authenticated attackers to access swimlane data from projects they are not authorized to view due to a missing project-level authorization check in the `getSwimlane` API method. To address this issue, users should upgrade Kanboard to version 1.2.50 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25530.
Read more Project Management