
CVE-2026-71285 Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript … https://www.cve.org/CVERecord?id=CVE-2026-71285
Post summary
The passage reveals a newly disclosed vulnerability (CVE‑2026‑71285) wherein Uptime Kuma’s Matomo integration widens an unquoted JavaScript injection, yet it offers no PoC, exploit, or mitigation details.


