CVE-2026-95656High· 7.3▾ MidnightPoC availableA vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Pe…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/init.py of the component Preview Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. Upgrading to version 0.60.1 is able to resolve this issue. The patch is named 71d332d5a0d3da2a0fe89a392413bf4b7d27c84e. The affected component should be upgraded. Was fixed upstream.
changedetection.io 50389b07Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-95657Low· 3.5dgtlmoon Changedetection.io Visual Selector visual-selector.js setCurrentSelectedText cross site scripting
CVE-2026-92815High· 7.5changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses
CVE-2026-95271High· 7.3A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-95273Medium· 4.3A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-95270Low· 3.7A flaw has been found in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-92814Medium· 4.2changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection