Enabling Authentication does not close all logged in socket connections immediately
Modified: 4/19/2024
package
pkg:npm/uptime-kuma
Enabling Authentication does not close all logged in socket connections immediately
Modified: 4/19/2024
uptime-kuma vulnerable to Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitor
Modified: 12/20/2024
Uptime Kuma vulnerable to authenticated remote code execution via malicious plugin installation
Modified: 9/10/2026
Password Change Vulnerability
Modified: 2/4/2026
Uptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors without needing to be on a status page
Modified: 3/14/2026
Uptime Kuma has Persistentent User Sessions
Modified: 2/4/2026
Uptime Kuma Authenticated remote code execution via TailscalePing
Modified: 11/27/2023
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Modified: 8/7/2025
Attribute Injection leading to XSS(Cross-Site-Scripting)
Modified: 9/10/2026
Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
Modified: 4/2/2026
Uptime Kuma's authenticated path traversal via plugin repository name may lead to unavailability or data loss
Modified: 9/10/2026