Known Vulnerabilities for products from Uptime-kuma Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Uptime-kuma Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-36822 json | Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allow... | 8.1 - HIGH | 2023-07-05 | 2023-07-12 |
| CVE-2023-36821 json | Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versi... | 8.8 - HIGH | 2023-07-05 | 2023-07-12 |
| CVE-2023-25811 json | Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a persisten... | 5.4 - MEDIUM | 2023-02-21 | 2023-03-03 |
| CVE-2023-25810 json | Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persistent XSS... | 5.4 - MEDIUM | 2023-02-21 | 2023-03-02 |