vciy

CVEs we hold for Oneuptime

Records whose assigning authority named Oneuptime as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-80350OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URLOneUptime
CVE-2026-45102OneUptime: RCE due to Node.js' vm module escape via error objects and infinite recursiononeuptime
CVE-2026-35053OneUptime: Unauthenticated Workflow Execution via ManualAPIoneuptime
CVE-2026-34840OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verificationoneuptime
CVE-2026-34759OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption…oneuptime
CVE-2026-34758OneUptime: Missing Authentication on Notification Endpointsoneuptime
CVE-2026-33396OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary…oneuptime
CVE-2026-33143OneUptime: WhatsApp Webhook Missing Signature Verificationoneuptime
CVE-2026-33142OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parametersoneuptime
CVE-2026-32598OneUptime: Password Reset Token Logged at INFO Leveloneuptime
CVE-2026-32308OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")oneuptime
CVE-2026-32306OneUptime ClickHouse SQL Injection via Aggregate Query Parametersoneuptime
CVE-2026-30959OneUptime has WhatsApp Resend Verification Authorization Bypassoneuptime
CVE-2026-30958OneUptime: Path Traversal — Arbitrary File Read (No Auth)oneuptime
CVE-2026-30957OneUptime Synthetic Monitor RCE via exposed Playwright browser objectoneuptime
CVE-2026-30956OneUptime has authorization bypass via client‑controlled is-multi-tenant-query headeroneuptime
CVE-2026-30921OneUptime Synthetic Monitor RCE via exposed Playwright browser objectoneuptime
CVE-2026-30920OneUptime has broken access control in GitHub App installation flow that allows unauthorized project bindingoneuptime
CVE-2026-30887OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCEoneuptime
CVE-2026-28787OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing…oneuptime
CVE-2026-27728OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()oneuptime
CVE-2026-27574OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCEoneuptime
CVE-2025-66028OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulationoneuptime
CVE-2025-65966OneUptime Unauthorized User Creation via APIoneuptime
CVE-2024-29194OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulationoneuptime

25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.