CVE-2026-40479General(kimai / kimai)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype and rendered through innerHTML, this incomplete escaping allows HTML attribute injection. An authenticated user with ROLE_USER privileges can store a malicious alias that executes JavaScript in the browser of any administrator viewing the team form, resulting in stored XSS with privilege escalation. This issue has been fixed in version 2.53.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kimai

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-18)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
kimai

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-18: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-18: 204-1604-18
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-161
General1
2026-04-182
Disclosure1General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40479 Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or s… https://www.cve.org/CVERecord?id=CVE-2026-40479

    Post summary

    The post announces CVE‑2026‑40479, describing a double‑quote escape failure in Kimai’s escapeForHtml() function affecting specific releases, and links to the CVE record for further details. No exploit, patch, or active exploitation is mentioned.

    00000102
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40479 Stored XSS via HTML Attribute Injection in Kimai 1.16.3 Through 2.52.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40479

    Post summary

    CVE-2026-40479 is a stored XSS vulnerability in Kimai 1.16.3 through 2.52.0 caused by HTML attribute injection. No PoC, exploit details, or patch information is provided in the text.

    0000072
    4.0K followersView on X
  • DailyCVE@dailycve
    General

    🟠 Kimai (time-tracking), Stored Cross-Site Scripting (XSS), #CVE-2026-40479 (Moderate) https://dailycve.com/kimai-time-tracking-stored-cross-site-scripting-xss-cve-2026-40479-moderate/

    Post summary

    The post refers to a stored XSS in Kimai (CVE‑2026‑40479) with moderate severity but offers no PoC, exploit, or patch information.

    0000025
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkimaikimai---

Explore more