CVE-2023-25810: Uptime-Kuma Project Uptime-Kuma
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persistent XSS attack. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
- Uptime-Kuma Project Uptime-Kuma: before 1.20.0 (fixed in 1.20.0)
Published 2023-02-21. Last modified 2026-06-17.