Kimai v2 before 1.1 has XSS via a timesheet description.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected