A high-severity stored cross-site scripting flaw, tracked as CVE-2026-71285, was disclosed in Uptime Kuma, the self-hosted monitoring tool maintained in the louislam/uptime-kuma project. The vulnerability affects versions up to and including 2.4.0 and stems from the product's Matomo analytics integration, where the admin-configurable siteId is inserted into a JavaScript block on public status pages without proper neutralization of characters such as ], ), ;, and (.
An attacker with editor or admin access can store a malicious value such as 1]);alert(document.cookie)//, which then executes arbitrary JavaScript when unauthenticated users visit /status/<slug> pages. The issue is rated CVSS 8.1 with vector AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N, and reported impact includes session-cookie theft and full compromise of the rendered page; recommended remediation is to validate and escape the Matomo siteId input and update Uptime Kuma to a fixed release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE record was published for a high-severity stored XSS vulnerability in Uptime Kuma's Matomo analytics integration affecting versions up to and including 2.4.0. The issue allows an editor or admin to save a malicious Matomo siteId that executes arbitrary JavaScript for visitors to public status pages.
The Uptime Kuma project was published on GitHub as a self-hosted monitoring tool repository under louislam/uptime-kuma.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.