VYPR

Changedetection.io

by Dgtlmoon

pypi: changedetection.io

Source repositories

CVEs (26)

  • CVE-2026-95270LowSep 22, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable timing discrepancy.…

  • CVE-2024-34061MedMay 2, 2024
    risk 0.21cvss 4.3epss 0.01

    changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in the application. A reflected XSS…

  • CVE-2026-92814MedSep 16, 2026
    risk 0.20cvss 4.2epss 0.00

    changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the…

  • CVE-2024-23329LowJan 19, 2024
    risk 0.17cvss 3.7epss 0.01

    changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch//history` can be accessed by any unauthorized user. As a result any unauthorized user can check one's watch history. However,…

  • CVE-2026-95657LowSep 22, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a manipulation of the argument s can lead to…

  • CVE-2025-62780LowNov 10, 2025
    risk 0.16cvss 3.5epss 0.00

    changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions prior to 0.50.34 due to insufficient security checks. Two scenarios are possible. In the first, an attacker can…

Page 2 of 2