28,679 Entries 2,229 Sources 5 Verticals Last sync 7 minutes Live
Dashboard/ Self-hosted apps/ Uptime Kuma
Self-hosted apps

Uptime Kuma

louislam
2.4.0 bewährt latest release
31.05.2026

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

18 CVE(s) zuletzt, höchste Schwere: hoch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
gh_etagW/"e867eead2a8242741638cf3a7f991f0e2795536db5a81c35c0d1062f2356d3fe"
gh_checked_at2026-06-08T03:00:00.127675+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows attackers to inject malicious JavaScript code into status page names, which then executes in other users' browsers and can compromise their sessions.

CVE-2023-25811
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows attackers to inject malicious JavaScript code into status page descriptions, which then executes when other users view those pages.

CVE-2023-25810
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Uptime Kuma monitoring software allows authenticated users to install malicious plugins that can automatically execute code on the server.

CVE-2023-36821
06.06.2026
CVE
Self-hosted apps Medium

A path traversal vulnerability in Uptime Kuma allows authenticated users to delete arbitrary files on the server by using manipulated plugin names, potentially causing system failure and data loss.

CVE-2023-36822
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma monitoring software causes user sessions to remain valid even after password changes or long periods of inactivity, allowing attackers with device access to gain persistent account access.

CVE-2023-44400
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows attackers to inject malicious code into web pages by manipulating the Google Analytics ID field in custom status pages, as user inputs are not properly sanitized.

CVE-2023-49276
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows authenticated users to execute arbitrary commands on the server by injecting malicious code into the hostname field of the Tailscale Ping monitor.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

Uptime Kuma fails to verify the origin of WebSocket connections, allowing third-party websites to access the application on behalf of their visitors and bypass firewall or proxy protections.

CVE-2023-49805
06.06.2026
CVE
Self-hosted apps Medium

Uptime Kuma has a vulnerability where logged-in users remain authenticated after password changes, allowing continued account access without re-authentication. This enables unauthorized access to user data even after passwords have been changed.

CVE-2023-49804
06.06.2026
CVE
Self-hosted apps Low

Uptime Kuma fails to automatically invalidate existing user sessions when authentication is enabled, allowing already logged-in users to retain full access until they manually log out or refresh the page.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows attackers to read local files from the server by using file:// URLs in the "real-browser" feature that takes screenshots, potentially exposing sensitive system files like /etc/passwd.

CVE-2024-56331
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows administrators to trigger a ReDoS attack through specially crafted URL inputs in notification settings, potentially freezing the web service due to excessive CPU usage.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows authenticated attackers to extract sensitive data from internal cloud metadata services through SSRF attacks, potentially exposing access tokens and configuration information.

Advisory
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Uptime Kuma allows unauthenticated attackers to access files starting with 'index.' through path traversal, potentially exposing sensitive information from the server's file system.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Uptime Kuma allows authenticated users to read arbitrary files from the server by injecting malicious templates into webhook notifications.

Advisory
06.06.2026
CVE
Self-hosted apps Low

Uptime Kuma sends RSS feeds for public status pages with incorrect content type as HTML instead of XML, causing browsers to misinterpret the feed and potentially execute scripts.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

A security flaw in Uptime Kuma allows unauthenticated users to retrieve average response times of private monitoring services because one API endpoint fails to verify proper authorization.

CVE-2026-32230
06.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in Uptime Kuma allows authenticated users to read arbitrary files from the server by using malicious templates in webhook notifications.

CVE-2026-33130
06.06.2026
REL
Self-hosted apps High bewährt

New SMS and chat notification providers, bearer token support for monitors, fix for remote code execution security vulnerability and various bug fixes

2.4.0
31.05.2026
REL
Self-hosted apps Low bewährt

Bug fix for SQLite database locking issue and dependency updates

2.3.1
03.05.2026
REL
Self-hosted apps Medium bewährt

SQLite database connection reverted from multiple connections back to single default connection

2.3.2
03.05.2026
REL
Self-hosted apps Medium bewährt

Removal of sorting feature on status pages and new SQLite configuration required for Raspberry Pi users

2.3.0
01.05.2026
REL
Self-hosted apps Medium bewährt

New Fluxer notification provider, bug fixes for UI styling and Prometheus metrics, plus security fix for server-side template injection

2.2.1
10.03.2026
REL
Self-hosted apps Medium bewährt

New features for SOCKS proxy support in notifications, WhatsApp provider and Signal templating, plus important bugfixes for Node.js compatibility and security vulnerability

2.2.0
05.03.2026
REL
Self-hosted apps Low bewährt

Added new notification providers and DNS support, fixed PWA cache issue and various bug fixes

2.1.2
19.02.2026
REL
Self-hosted apps Low bewährt

Bug fix for non-functioning RDAP data caching

2.1.3
19.02.2026
REL
Self-hosted apps Low bewährt

Uptime Kuma 2.1.1 adds customizable Matrix notifications, group name column in dashboard and fixes several bugs in Gamedig, Discord notifications and domain expiry monitoring

2.1.1
13.02.2026
REL
Self-hosted apps Medium bewährt

Uptime Kuma 2.1.0 adds new notification providers (Jira Service Management, Google Sheets) and fixes various bugs related to certificates, monitoring, and UI behavior

2.1.0
07.02.2026
REL
Self-hosted apps Low bewährt

Beta version with new features including Google Sheets notifications, incident history, PostgreSQL query monitoring and various improvements plus bug fixes

2.1.0-beta.3
22.01.2026
REL
Self-hosted apps Low bewährt

Beta version with new monitor types (SIP, MySQL/MariaDB), enhanced notification options, Docker secrets support and various UI improvements

2.1.0-beta.2
14.01.2026
REL
Self-hosted apps Medium Breaking

Beta version with new monitor types (SQL Server, system services, domain expiry), analytics support for status pages and removal of LINE Notify integration

2.1.0-beta.1
05.01.2026
REL
Self-hosted apps Low bewährt

Beta version with new features including webpush notifications, SSL/STARTTLS for TCP port monitoring, improved HeartbeatBar performance and various bug fixes

2.1.0-beta.0
20.12.2025
REL
Self-hosted apps Low bewährt

Fixes false positive detection of Google Chrome during migration and updates security documentation

2.0.2
22.10.2025
REL
Self-hosted apps High bewährt

Security update fixes server-side template injection vulnerability in notification templates and browser monitor issue

1.23.17
20.10.2025
REL
Self-hosted apps High Breaking

Uptime Kuma 2.0.0 is a major release with breaking changes, new notification providers, security fixes and requires careful migration from v1

2.0.0
20.10.2025
REL
Self-hosted apps Medium bewährt

Fixes a bug where healthchecks could cause unexpected shutdown of Uptime Kuma during data migration

2.0.1
20.10.2025
REL
Self-hosted apps High Breaking

Uptime Kuma 2.0.0-beta.4 introduces new features like manual monitors, markdown support and bulk tag management, but contains breaking changes requiring migration

2.0.0-beta.4
05.09.2025
REL
Self-hosted apps High bewährt

Beta version with new notification providers, enhanced ping monitor options and important security fixes for unauthenticated file access

2.0.0-beta.3
04.06.2025
REL
Self-hosted apps Medium Breaking

Beta version with new notification providers, security fixes for ReDoS vulnerabilities and various improvements

2.0.0-beta.2
28.03.2025
REL
Self-hosted apps High bewährt

Security update fixes local file inclusion vulnerability in Real-Browser monitor and updates dependencies

1.23.16
20.12.2024
REL
Self-hosted apps High Breaking

Beta version 2.0.0 with critical security fixes for Local File Inclusion vulnerability, Docker images on ghcr.io and various bug fixes

2.0.0-beta.1
20.12.2024
REL
Self-hosted apps High Breaking

Uptime Kuma 2.0.0-beta.0 with numerous new features like MariaDB support, SNMP monitor and many notification providers, but includes breaking changes requiring migration

2.0.0-beta.0
29.10.2024
REL
Self-hosted apps Medium bewährt

Bug fixes for API key display and status page icons along with security updates for dependencies

1.23.14
29.09.2024
REL
Self-hosted apps Medium bewährt

Fixes crash issue from version 1.23.14 by pinning cheerio dependency for Alpine images and Node.js 16

1.23.15
29.09.2024
REL
Self-hosted apps Low bewährt

Bug fixes for language settings and TLS certificate issues with proxy connections

1.23.13
25.04.2024
REL
Self-hosted apps High Breaking

Security updates for multiple dependencies, improvements to TLS certificate detection and i18n language detection, but proxy users should stay on version 1.23.11

1.23.12
18.04.2024
REL
Self-hosted apps Low bewährt

Updated dependencies and fixed error handling bug and Tailscale monitor issue

1.23.11
30.12.2023
REL
Self-hosted apps High bewährt

Security fix for incompletely patched vulnerability and improvement of reverse proxy configuration

1.23.10
12.12.2023