PatchSiren

louislam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH louislam CVE published 2026-08-05

CVE-2026-71285

Uptime Kuma's Matomo analytics integration is vulnerable to JavaScript injection due to insufficient escaping of the siteId value. This allows an attacker to inject arbitrary JavaScript code, potentially leading to session-cookie theft and full page takeover. The vulnerability exists in the server/analytics/matomo-analytics.js file, where the admin-configurable Matomo siteId value is injected as a bare, u [truncated]