{"schema_version":1,"title":"Louis Lam vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in Louis Lam: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73040, was published on 20 August 2026.","url":"https://junglewise.ai/threats/vendors/louis-lam","json_url":"https://junglewise.ai/threats/vendors/louis-lam.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/louis-lam","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":8,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":2},"latest":[{"cve":"CVE-2026-73040","cvss":8.8,"epss":0.0094,"slug":"cve-2026-73040-dockge-path-traversal-in-stack-operations","title":"Dockge path traversal in stack operations","severity":"high","exploited":false,"published_at":"2026-08-20T21:17:09.11+00:00","url":"https://junglewise.ai/threats/cve-2026-73040-dockge-path-traversal-in-stack-operations"},{"cvss":3.1,"slug":"uptime-kuma-server-side-template-injection-in-notification-templates-8547405a","title":"Uptime Kuma Server-side Template Injection in notification templates","severity":"low","exploited":false,"published_at":"2025-10-20T20:03:15+00:00","url":"https://junglewise.ai/threats/uptime-kuma-server-side-template-injection-in-notification-templates-8547405a"},{"cve":"CVE-2023-36821","cvss":3.1,"epss":0.0202,"slug":"cve-2023-36821-uptime-kuma-authenticated-remote-code-execution-via-plugin","title":"Uptime Kuma authenticated remote code execution via plugin installation","severity":"low","exploited":false,"published_at":"2024-05-01T10:01:24+00:00","url":"https://junglewise.ai/threats/cve-2023-36821-uptime-kuma-authenticated-remote-code-execution-via-plugin"},{"cve":"CVE-2023-36822","cvss":3.1,"epss":0.0121,"slug":"cve-2023-36822-uptime-kuma-path-traversal-in-plugin-installation","title":"Uptime Kuma path traversal in plugin installation","severity":"low","exploited":false,"published_at":"2024-05-01T10:01:02+00:00","url":"https://junglewise.ai/threats/cve-2023-36822-uptime-kuma-path-traversal-in-plugin-installation"},{"cve":"CVE-2023-49804","cvss":3.1,"epss":0.0026,"slug":"cve-2023-49804-uptime-kuma-session-persistence-after-password-change","title":"Uptime Kuma session persistence after password change","severity":"low","exploited":false,"published_at":"2023-12-12T00:59:30+00:00","url":"https://junglewise.ai/threats/cve-2023-49804-uptime-kuma-session-persistence-after-password-change"},{"slug":"uptime-kuma-authenticated-remote-code-execution-via-tailscaleping-b849ee74","title":"Uptime Kuma authenticated remote code execution via TailscalePing","severity":"info","exploited":false,"published_at":"2023-11-27T17:25:11+00:00","url":"https://junglewise.ai/threats/uptime-kuma-authenticated-remote-code-execution-via-tailscaleping-b849ee74"},{"cve":"CVE-2023-49276","cvss":3.1,"epss":0.005,"slug":"cve-2023-49276-louis-lam-uptime-kuma-attribute-injection-leading-to-xss","title":"Louis Lam Uptime Kuma attribute injection leading to XSS","severity":"low","exploited":false,"published_at":"2023-11-24T16:54:20+00:00","url":"https://junglewise.ai/threats/cve-2023-49276-louis-lam-uptime-kuma-attribute-injection-leading-to-xss"},{"cve":"CVE-2023-44400","cvss":3.1,"epss":0.0027,"slug":"cve-2023-44400-uptime-kuma-persistent-session-tokens-after-password-change","title":"Uptime Kuma persistent session tokens after password change","severity":"low","exploited":false,"published_at":"2023-10-10T21:29:23+00:00","url":"https://junglewise.ai/threats/cve-2023-44400-uptime-kuma-persistent-session-tokens-after-password-change"}],"vendor":{"hub":true,"name":"Louis Lam","slug":"louis-lam","url":"https://junglewise.ai/threats/vendors/louis-lam"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-73040","cvss":8.8,"epss":0.0094,"slug":"cve-2026-73040-dockge-path-traversal-in-stack-operations","title":"Dockge path traversal in stack operations","severity":"high","exploited":false,"published_at":"2026-08-20T21:17:09.11+00:00","url":"https://junglewise.ai/threats/cve-2026-73040-dockge-path-traversal-in-stack-operations"},{"cve":"CVE-2023-36821","cvss":3.1,"epss":0.0202,"slug":"cve-2023-36821-uptime-kuma-authenticated-remote-code-execution-via-plugin","title":"Uptime Kuma authenticated remote code execution via plugin installation","severity":"low","exploited":false,"published_at":"2024-05-01T10:01:24+00:00","url":"https://junglewise.ai/threats/cve-2023-36821-uptime-kuma-authenticated-remote-code-execution-via-plugin"},{"cve":"CVE-2023-36822","cvss":3.1,"epss":0.0121,"slug":"cve-2023-36822-uptime-kuma-path-traversal-in-plugin-installation","title":"Uptime Kuma path traversal in plugin installation","severity":"low","exploited":false,"published_at":"2024-05-01T10:01:02+00:00","url":"https://junglewise.ai/threats/cve-2023-36822-uptime-kuma-path-traversal-in-plugin-installation"},{"cve":"CVE-2023-49276","cvss":3.1,"epss":0.005,"slug":"cve-2023-49276-louis-lam-uptime-kuma-attribute-injection-leading-to-xss","title":"Louis Lam Uptime Kuma attribute injection leading to XSS","severity":"low","exploited":false,"published_at":"2023-11-24T16:54:20+00:00","url":"https://junglewise.ai/threats/cve-2023-49276-louis-lam-uptime-kuma-attribute-injection-leading-to-xss"},{"cve":"CVE-2023-44400","cvss":3.1,"epss":0.0027,"slug":"cve-2023-44400-uptime-kuma-persistent-session-tokens-after-password-change","title":"Uptime Kuma persistent session tokens after password change","severity":"low","exploited":false,"published_at":"2023-10-10T21:29:23+00:00","url":"https://junglewise.ai/threats/cve-2023-44400-uptime-kuma-persistent-session-tokens-after-password-change"},{"cve":"CVE-2023-49804","cvss":3.1,"epss":0.0026,"slug":"cve-2023-49804-uptime-kuma-session-persistence-after-password-change","title":"Uptime Kuma session persistence after password change","severity":"low","exploited":false,"published_at":"2023-12-12T00:59:30+00:00","url":"https://junglewise.ai/threats/cve-2023-49804-uptime-kuma-session-persistence-after-password-change"},{"cvss":3.1,"slug":"uptime-kuma-server-side-template-injection-in-notification-templates-8547405a","title":"Uptime Kuma Server-side Template Injection in notification templates","severity":"low","exploited":false,"published_at":"2025-10-20T20:03:15+00:00","url":"https://junglewise.ai/threats/uptime-kuma-server-side-template-injection-in-notification-templates-8547405a"},{"slug":"uptime-kuma-authenticated-remote-code-execution-via-tailscaleping-b849ee74","title":"Uptime Kuma authenticated remote code execution via TailscalePing","severity":"info","exploited":false,"published_at":"2023-11-27T17:25:11+00:00","url":"https://junglewise.ai/threats/uptime-kuma-authenticated-remote-code-execution-via-tailscaleping-b849ee74"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[]}