Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21694 +1 in the same advisory: …21695 | Titra is open source project time tracking software. Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50. NVD description · AI analysis pending | 8.1 group max | <1% | PoC |
| — | |
| CVE-2025-69288 | Titra is open source project time tracking software. Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue. NVD description · AI analysis pending | 9.1 | <1% | PoC |
| — | |
| CVE-2022-2595 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. NVD description · AI analysis pending | 10.0 | 1% | PoC |
| — | |
| CVE-2022-2098 | Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-2027 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. NVD description · AI analysis pending | 8.0 group max | 1% | PoC |
| — |