CVE-2026-95270Low· 3.7▾ TwilightPoC availableA flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Passwor…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 20.4 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable timing discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-95656High· 7.3A vulnerability was found in dgtlmoon changedetection.io up to 50389b07
CVE-2026-95271High· 7.3A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-95272Low· 3.7A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-95273Medium· 4.3A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-92814Medium· 4.2changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection
CVE-2026-92815High· 7.5changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses