Skip to content

kimai

v2.60.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

doctrine invoice invoicing kimai multilanguage php
+9 more
self-hosted symfony tabler time-tracker time-tracking timetracker timetracking timetrackingapp twig

ReleasePort's take

Light signal
editorial:auto 1mo

Kimaiβ€―2.60.0 adds watermark options to the PDF generation API and fixes a missing default‑user filter in invoice archives.

Why it matters: The new watermark-text and watermark-image parameters let developers brand exported PDFs directly; fixing the missing "default user" entry restores reliable filtering for archived invoices.

Summary

AI summary

Updates Bugfixes, 🚨 Security, and https://www.kimai.org/security.xml across a mixed release.

Changes in this release

Security High

Improves whitespace handling in Search term parser to mitigate injection risks

Improves whitespace handling in Search term parser to mitigate injection risks

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Adds watermark-text and watermark-image options for PDFs (excluding PDFa/PDFx)

Adds watermark-text and watermark-image options for PDFs (excluding PDFa/PDFx)

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Fixes missing "default user" in invoice archive query, making filter visible

Fixes missing "default user" in invoice archive query, making filter visible

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Full changelog

Compatible with PHP 8.2 to 8.5

Features

  • Added options to allow watermark-text and watermark-image in PDF (not allowed for PDFa/PDFx) usable in twig templates e.g. to define a background image
  • Translations update from Hosted Weblate (#5973)

Bugfixes

  • Added missing "default user" in invoice archive query (fixes invisible filter) (#5971)

🚨 Security

  • Improve whitespace handling in Search term parser (#5977) - thanks @tikket1

You can read more about all security reports here or grab this RSS feed to get notified about new published advisories.

Involved in this release: @kevinpapst

Security Fixes

  • Improve whitespace handling in Search term parser (#5977) β€” mitigates potential injection abuse

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kimai

Get notified when new releases ship.

Sign up free

About kimai

Kimai is the #1 open-source time-tracking application. From freelancers to companies and organisations - everyone can manage timesheets, generate reports, create invoices and so much more... Web-based multi-user application, available as On-Premise or SaaS version: https://www.kimai.org

All releases β†’

Related context

Related tools

Beta — feedback welcome: [email protected]