Uptime Kuma is a lightweight, self-hosted monitoring and status-page application whose vulnerability profile centers on cross-site scripting weaknesses in web-page generation, reflecting the challenges of sanitizing user input in a dashboard-oriented tool. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uptime Kuma Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36821HIGH Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versions prior to 1.22.1, which may lead to remote code exec | Jul 5, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-36822HIGH Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to install plugins from an offici | Jul 5, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-26777MEDIUM Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, an | Apr 4, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-25811MEDIUM Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a persistent XSS attack. Users are advised to upgrade. There are n | Feb 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-25810MEDIUM Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persistent XSS attack. Users are advised to upgrade. There are no kno | Feb 21, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uptime Kuma Project.
Media articles that mention a CVE ID that affects a product developed by Uptime Kuma Project — matched by CVE ID, not by vendor name.