changedetection-io
PyPI20 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting changedetection-iopage 1 of 1
- CVE-2023-24769MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.40.1.12023-02-17
vulnerable: 0.38.2 ... 0.40.1.0 (43 versions)
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected i…
- CVE-2024-23329LOWCVSS 3.7EG 3.7✓ Fixed in 0.45.132024-01-19
vulnerable: 0.39.14 ... 0.45.9 (54 versions)
changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any unauthorized user. As a result any unauthorized user c…
- CVE-2024-32651CRITICALCVSS 10.0EG 10.0✓ Fixed in 0.45.212024-04-26
vulnerable: 0.38.2 ... 0.45.9 (80 versions)
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. …
- CVE-2024-34061MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.45.222024-05-02
vulnerable: 0.38.2 ... 0.45.9 (81 versions)
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in …
- CVE-2024-51483MEDIUMCVSS 6.9EG 6.9✓ Fixed in 0.47.52024-11-01
vulnerable: 0.38.2 ... 0.47.4 (96 versions)
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditiona…
- CVE-2024-51998HIGHCVSS 8.6EG 8.6✓ Fixed in 0.47.62024-11-08
vulnerable: 0.38.2 ... 0.47.5 (97 versions)
changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker being able to read any file on the system. This issue only affects instances with a web…
- CVE-2024-56509HIGHCVSS 8.6EG 8.6✓ Fixed in 0.48.052024-12-27
vulnerable: 0.38.2 ... 0.48.4 (103 versions)
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow attackers to perform local file read (LFR) or path traver…
- CVE-2025-52558HIGHCVSS 7.0EG 7.0✓ Fixed in 0.50.42025-06-23
vulnerable: 0.38.2 ... 0.50.3 (126 versions)
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered re…
- CVE-2025-62780MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.50.342025-11-10
vulnerable: 0.38.2 ... 0.50.9 (156 versions)
changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions prior to 0.50.34 due to insufficient security checks. Two scenarios are po…
- CVE-2026-25527MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.53.22026-07-20
vulnerable: 0.38.2 ... 0.53.1 (180 versions)
changedetection.io is vulnerable to unauthenticated static path traversal ## Summary The `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base di…
- CVE-2026-27645MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.54.12026-02-25
vulnerable: 0.38.2 ... 0.53.7 (186 versions)
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML escaping. Since Flask retu…
- CVE-2026-27696HIGHCVSS 8.6EG 8.6✓ Fixed in 0.54.12026-02-25
vulnerable: 0.38.2 ... 0.53.7 (186 versions)
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function `is_safe_valid_url()` does not…
- CVE-2026-29038MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.54.42026-03-06
vulnerable: 0.38.2 ... 0.54.3 (189 versions)
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected cross-site scripting (XSS) vulnerability identified in the /rss/tag/ endpoint of changedetection.io. The tag_uuid path p…
- CVE-2026-29039HIGHCVSS 7.5EG 7.5✓ Fixed in 0.54.42026-03-06
vulnerable: 0.38.2 ... 0.54.3 (189 versions)
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters field. These XPath ex…
- CVE-2026-29065CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.54.42026-03-06
vulnerable: 0.38.2 ... 0.54.3 (189 versions)
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. Thi…
- CVE-2026-33981MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.54.72026-03-27
vulnerable: 0.38.2 ... 0.54.6 (192 versions)
changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which reads all process environment variables and stores them as…
- CVE-2026-35000MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.54.72026-04-01
vulnerable: 0.38.2 ... 0.54.6 (192 versions)
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() …
- CVE-2026-35490CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.54.82026-04-07
vulnerable: 0.38.2 ... 0.54.7 (193 versions)
changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost…
- CVE-2026-41895HIGHCVSS 7.5EG 7.5✓ Fixed in 0.54.102026-05-12
vulnerable: 0.38.2 ... 0.54.9 (195 versions)
changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external en…
- CVE-2026-43891HIGHCVSS 7.5EG 7.5✓ Fixed in 0.55.12026-05-12
vulnerable: 0.38.2 ... 0.54.9 (196 versions)
changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vulnerable flow starts in the backup resto…
Check whether changedetection-io is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for changedetection-io CVEs against the assets you own.
Start Free Scan →