<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
>
    <channel>
        <title xml:lang="en">Kimai Security Advisories</title>
        <atom:link type="application/atom+xml" href="/security.xml" rel="self"/>
        <link>https://www.kimai.org/</link>
        <pubDate>Wed, 06 May 2026 18:26:29 +0200</pubDate>
        <lastBuildDate>Wed, 06 May 2026 18:26:29 +0200</lastBuildDate>
        <language>en</language>
        <description>Security advisories for Kimai Time-Tracker</description>
        <image>
            <description>Kimai Logo</description>
            <url>/images/apple-touch-icon.png</url>
            <title>Kimai</title>
            <link>https://www.kimai.org/</link>
            <width>184</width>
            <height>184</height>
        </image>
        
        <item>
            <title>Authenticated SSTI to RCE by uploading a malicious twig file</title>
            <link>https://www.kimai.org/en/security/ghsa-fjhg-96cp-6fcw</link>
            <pubDate>Fri, 27 Oct 2023 18:27:17 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-fjhg-96cp-6fcw</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-fjhg-96cp-6fcw">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>API returns timesheet entries a user shouldn&apos;t be authorized to view</title>
            <link>https://www.kimai.org/en/security/ghsa-cj3c-5xpm-cx94</link>
            <pubDate>Wed, 27 Mar 2024 22:58:18 +0100</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-cj3c-5xpm-cx94</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-cj3c-5xpm-cx94">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>XXE leading to local file read</title>
            <link>https://www.kimai.org/en/security/ghsa-534c-hcr7-67jg</link>
            <pubDate>Tue, 17 Sep 2024 08:18:39 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-534c-hcr7-67jg</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-534c-hcr7-67jg">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>Authenticated server-side template injection (SSTI)</title>
            <link>https://www.kimai.org/en/security/ghsa-jg2j-2w24-54cg</link>
            <pubDate>Sun, 18 Jan 2026 17:06:10 +0100</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-jg2j-2w24-54cg</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-jg2j-2w24-54cg">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>API invoice endpoint missing customer-level access control (IDOR)</title>
            <link>https://www.kimai.org/en/security/ghsa-v33r-r6h2-8wr7</link>
            <pubDate>Wed, 04 Mar 2026 13:43:17 +0100</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-v33r-r6h2-8wr7</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-v33r-r6h2-8wr7">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>Open-redirect via unvalidated RelayState in SAML ACS handler</title>
            <link>https://www.kimai.org/en/security/ghsa-3jp4-mhh4-gcgr</link>
            <pubDate>Sat, 11 Apr 2026 23:22:05 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-3jp4-mhh4-gcgr</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-3jp4-mhh4-gcgr">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>API password hash leakage via invoice Twig template</title>
            <link>https://www.kimai.org/en/security/ghsa-rh42-6rj2-xwmc</link>
            <pubDate>Sat, 11 Apr 2026 23:49:17 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-rh42-6rj2-xwmc</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-rh42-6rj2-xwmc">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>Stored XSS via incomplete HTML attribute escaping in Team-Member widget</title>
            <link>https://www.kimai.org/en/security/ghsa-g82g-m9vx-vhjg</link>
            <pubDate>Tue, 14 Apr 2026 16:03:14 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-g82g-m9vx-vhjg</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-g82g-m9vx-vhjg">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>User Preferences API allows standard users to modify: hourly_rate, internal_rate</title>
            <link>https://www.kimai.org/en/security/ghsa-qh43-xrjm-4ggp</link>
            <pubDate>Tue, 14 Apr 2026 16:05:11 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-qh43-xrjm-4ggp</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-qh43-xrjm-4ggp">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
        <item>
            <title>Username enumeration via timing, using deprecated API authentication</title>
            <link>https://www.kimai.org/en/security/ghsa-jrc6-fmhw-fpq2</link>
            <pubDate>Thu, 16 Apr 2026 23:19:11 +0200</pubDate>
            <guid isPermaLink="true">https://www.kimai.org/en/security/ghsa-jrc6-fmhw-fpq2</guid>
            <description>
                <![CDATA[
                        <a href="https://www.kimai.org/en/security/ghsa-jrc6-fmhw-fpq2">Read the full advisory here</a>
                    ]]>
            </description>
        </item>
        
    </channel>
</rss>
