Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/oneuptime — 5 CVEs · VulnScope
pkg:npm/
oneuptime
5 total CVEs
CRITICAL
1
HIGH
2
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.9
CVE-2026-32306
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
from 0, < 10.0.23
HIGH
8.1
CVE-2026-33142
OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
from 0, < 10.0.34
HIGH
7.6
CVE-2026-32308
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
from 0, < 10.0.23
—
OneUptime WhatsApp Webhook Missing Signature Verification
from 0, < 10.0.34
—
OneUptime: Password Reset Token Logged at INFO Level
from 0, < 10.0.23
CVE-2026-33143
CVE-2026-32598