Vulnerabilities > Kimai > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-02-15 CVE-2020-19825 Cross-site Scripting vulnerability in Kimai 1.30.0
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
network
low complexity
kimai CWE-79
critical
9.6
2021-12-01 CVE-2021-3985 Unspecified vulnerability in Kimai Kimai2
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
low complexity
kimai
critical
9.0