Skip to main content
Loading…
    CVE-2026-28685 — Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify the requesti — CVE Database · The Intelligence Room