« Back to list

Changedetection

Changedetection.io: vulnerabilities and CVEs

Changedetection.io has 9 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-92815High (8.7)0.54%—Sep 16, 2026
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the…
CVE-2026-92814Low (2.3)0.30%—Sep 16, 2026
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches…
CVE-2026-71205Medium (6.5)0.27%—Aug 5, 2026
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is…
CVE-2026-71204Medium (6.2)0.32%—Aug 5, 2026
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.
CVE-2025-52558High (7)0.59%—Jun 23, 2025
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were…
CVE-2024-56509High (8.6)0.70%—Dec 27, 2024
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow attackers to perform local file read…
CVE-2024-51483Medium (6.9)2.3%—Nov 1, 2024
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where…
CVE-2024-34061Medium (4.3)1.3%—May 2, 2024
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in…
CVE-2024-32651Critical (10)84%—Apr 26, 2024
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1090 Proxy1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Changedetection