← Vulnerability feed

Vulnerability record · CVE-2025-69288 · published 31 December 2025

CVE-2025-69288: Kromit titra improper input validation vulnerability

KKromit · Titra

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

9.1 CVSS 3.1 Critical EPSS 0.85% · top 43.5% CWE-20 · Improper input validation
9.1CVSS 3.1 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
23 Sep 2026Last modified by NVD

Description

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-69288 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-2595Kromit titra improper authorization vulnerabilityImproper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.EPSS 1.3%9.8CVE-2022-2098Kromit titra weak password requirements vulnerabilityWeak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.EPSS 1.0%8.1CVE-2026-21694Kromit titra improper access control vulnerabilityTitra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other u…EPSS 0.28%8.0CVE-2022-2027Kromit titra csv injection vulnerabilityImproper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 1.2%5.4CVE-2022-2026Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%5.4CVE-2022-2028Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%5.4CVE-2022-2029Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%4.3CVE-2026-21695Kromit titra mass assignment vulnerabilityTitra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authentic…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2025-69288), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.