Skip to main content

Vendor/product archive

uptime.kuma / uptime_kuma CVEs

Beta · best-effort

6 CVEs tagged to uptime.kuma / uptime_kuma0 Critical, 0 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-33130

Published Mar 20, 2026

Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to preventServer-side Template In…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32230

Published Mar 12, 2026

Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify t…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2023-49276

Published Dec 1, 2023

Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44400

Published Oct 9, 2023

Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verif…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1