Uptime.Kuma

Uptime Kuma

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.03.2026 09:50:55
  • Zuletzt bearbeitet 24.03.2026 15:24:16

Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to preventServer-side Template Injection (SSTI). The three mitigations added to the Liquid engine (root,...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 12.03.2026 18:13:58
  • Zuletzt bearbeitet 19.03.2026 21:06:13

Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify that the requested monitor belongs to a public group. All other badge en...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 11.12.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:33:52

Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to access the appli...

  • EPSS 0.05%
  • Veröffentlicht 11.12.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:33:52

Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, eve...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 01.12.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 08:33:10

Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (XSS). Since the custom status interface can set an independent Google A...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 09.10.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:25:49

Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactiv...