CVE-2026-71285 | louislam Uptime Kuma up to 2.4.0 Matomo Analytics Integration matomo-analytics.js html-escaper.escape siteId cross site scripting
A vulnerability has been found in louislam Uptime Kuma up to 2.4.0 and classified as problematic. Affected by this vulnerability is the function html-escaper.escape of the file server/analytics/matomo-analytics.js of the component Matomo Analytics Integration. This manipulation of the argument siteId causes cross site scripting.
This vulnerability is handled as CVE-2026-71285. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More