
CVE-2026-40479 Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or s… https://www.cve.org/CVERecord?id=CVE-2026-40479
Post summary
The post announces CVE‑2026‑40479, describing a double‑quote escape failure in Kimai’s escapeForHtml() function affecting specific releases, and links to the CVE record for further details. No exploit, patch, or active exploitation is mentioned.


