VYPR
Vendor

Uptime.kuma

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2023-49804MedDec 11, 2023
    risk 0.37cvss 6.7epss 0.00

    Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, even after system restarts or…

  • CVE-2023-44400MedOct 9, 2023
    risk 0.37cvss 6.7epss 0.00

    Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3…

  • CVE-2026-33130MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to preventServer-side Template Injection (SSTI). The three mitigations added to the Liquid engine (root, relativeReference,…

  • CVE-2023-49276MedDec 1, 2023
    risk 0.34cvss 6.3epss 0.01

    Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (XSS). Since the custom status interface can set an independent Google Analytics ID and the template…

  • CVE-2026-32230MedMar 12, 2026
    risk 0.28cvss 5.3epss 0.01

    Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify that the requested monitor belongs to a public group. All other badge endpoints check AND public = 1…

  • CVE-2023-49805MedDec 11, 2023
    risk 0.00cvss 6.0epss 0.00

    Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to access the application on behalf of their…