Skip to content

Known CVE

OneUptime < 10.0.21 - Path Traversal

OneUptime < 10.0.21 contains a path traversal caused by unsanitized componentName parameter in /workflow/docs/:componentName endpoint, letting unauthenticated attackers read arbitrary files from the server filesystem.

CVE-2026-30958

High2026CVSS 7.2CWE-22

cve2026 · oneuptime · lfi · path-traversal · vuln · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website