Medium severity6.1NVD Advisory· Published Apr 4, 2023· Updated Jun 17, 2026
CVE-2023-26777
CVE-2023-26777
Description
Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:uptime_kuma_project:uptime_kuma:*:*:*:*:*:*:*:*Range: <=1.19.6
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=1.19.6
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/171699/Uptime-Kuma-1.19.6-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- github.com/louislam/uptime-kuma/issues/2186nvdIssue Tracking
News mentions
0No linked articles in our index yet.