Webtechnologies
Webtechnologies Changedetection: vulnerabilidades y CVE
Webtechnologies Changedetection tiene 13 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses11
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-43891 | Alta (7.5) | 0.50% | — | 12 may 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vulnerable flow starts… |
| CVE-2026-41895 | Alta (8.2) | 0.37% | — | 12 may 2026 | changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly… |
| CVE-2026-35490 | Crítica (9.8) | 0.64% | — | 7 abr 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route()… |
| CVE-2026-35000 | Alta (7.1) | 0.47% | — | 1 abr 2026 | ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions… |
| CVE-2026-33981 | Alta (8.3) | 0.48% | — | 27 mar 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which reads all process environment… |
| CVE-2026-29065 | Alta (8.8) | 0.56% | — | 6 mar 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in… |
| CVE-2026-29039 | Alta (8.8) | 0.51% | — | 6 mar 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters… |
| CVE-2026-29038 | Media (6.1) | 0.34% | — | 6 mar 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected cross-site scripting (XSS) vulnerability identified in the /rss/tag/ endpoint of changedetection.io.… |
| CVE-2026-27696 | Alta (8.6) | 0.48% | — | 25 feb 2026 | changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function… |
| CVE-2026-27645 | Media (6.1) | 0.49% | — | 25 feb 2026 | changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML… |
| CVE-2026-25527 | Media (5.3) | 0.89% | — | 19 feb 2026 | changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..",… |
| CVE-2024-23329 | Baja (3.7) | 0.59% | — | 19 ene 2024 | changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any unauthorized user. As a result any… |
| CVE-2023-24769 | Media (5.4) | 0.64% | — | 17 feb 2023 | Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.