VendorsWeb Technologieschangedetectionall versions
Vulnerabilities

Web Technologies Change Detection

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2026-35490
changedetection.io has an Authentication Bypass via Decorator Ordering
Published 2026-04-07 · Analyzed
9.8EPSS 0.006
CVE-2026-29065
changedetection.io: Zip Slip vulnerability in the backup restore functionality
Published 2026-03-06 · Analyzed
9.1EPSS 0.006
CVE-2026-29039
changedetection.io: XPath - Arbitrary File Read via unparsed-text()
Published 2026-03-06 · Analyzed
8.8EPSS 0.005
CVE-2026-27696
changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs
Published 2026-02-25 · Analyzed
8.6EPSS 0.005
CVE-2026-33981
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
Published 2026-03-27 · Analyzed
8.3EPSS 0.005
CVE-2026-41895
changedetection.io: XXE vulnerability in the changedetection.io project
Published 2026-05-12 · Analyzed
8.2EPSS 0.004
CVE-2026-43891
changedetection.io: Arbitrary Local File Read via crafted backup restore
Published 2026-05-12 · Analyzed
7.5EPSS 0.005
CVE-2026-35000
ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read
Published 2026-04-01 · Analyzed
7.1EPSS 0.005
CVE-2026-27645
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
Published 2026-02-25 · Analyzed
6.1EPSS 0.005
CVE-2026-29038
changedetection.io: Reflected XSS in RSS Tag Error Response
Published 2026-03-06 · Analyzed
6.1EPSS 0.003
CVE-2023-24769
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
Published 2023-02-17 · Modified
5.4EPSS 0.006
CVE-2026-25527
changedetection.io vulnerable to unauthenticated static path traversal
Published 2026-02-19 · Analyzed
5.3EPSS 0.009
CVE-2024-23329
changedetection.io API endpoint is not secured with API token
Published 2024-01-19 · Modified
3.7EPSS 0.006