CVE-2019-25317EPSS p21.1%
CVE-2019-25317CVE-2019-25317
kimai / kimai
Description
Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.
Scoring
| CVSS | 6.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
| EPSS | 0.30% probability of exploitation · percentile 21.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |