« Volver al listado

Webtechnologies

Webtechnologies Changedetection: vulnerabilidades y CVE

Webtechnologies Changedetection tiene 13 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses11
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-43891Alta (7.5)0.50%—12 may 2026
changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vulnerable flow starts…
CVE-2026-41895Alta (8.2)0.37%—12 may 2026
changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly…
CVE-2026-35490Crítica (9.8)0.64%—7 abr 2026
changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route()…
CVE-2026-35000Alta (7.1)0.47%—1 abr 2026
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions…
CVE-2026-33981Alta (8.3)0.48%—27 mar 2026
changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which reads all process environment…
CVE-2026-29065Alta (8.8)0.56%—6 mar 2026
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in…
CVE-2026-29039Alta (8.8)0.51%—6 mar 2026
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters…
CVE-2026-29038Media (6.1)0.34%—6 mar 2026
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected cross-site scripting (XSS) vulnerability identified in the /rss/tag/ endpoint of changedetection.io.…
CVE-2026-27696Alta (8.6)0.48%—25 feb 2026
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function…
CVE-2026-27645Media (6.1)0.49%—25 feb 2026
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML…
CVE-2026-25527Media (5.3)0.89%—19 feb 2026
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..",…
CVE-2024-23329Baja (3.7)0.59%—19 ene 2024
changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any unauthorized user. As a result any…
CVE-2023-24769Media (5.4)0.64%—17 feb 2023
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1005 Data from Local System5
  3. T1210 Exploitation of Remote Services2
  4. T1078 Valid Accounts1
  5. T1090 Proxy1
  6. T1565 Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.