<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Kuma (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/kuma.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kuma-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Kuma (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-36542 – Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36542</guid>
    <pubDate>Thu, 25 Jul 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36542</strong></p>
  <p>Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36821 – Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36821</guid>
    <pubDate>Wed, 05 Jul 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36821</strong></p>
  <p>Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versions prior to 1.22.1, which may lead to remote code execution. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in the web interface, but the corresponding API endpoints are still available after l…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36821">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
