CVE-2023-25811: Uptime-Kuma Project Uptime-Kuma

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a persistent XSS attack. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

Published 2023-02-21. Last modified 2026-06-17.