dgtlmoon has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 4.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Worst active — by depth score
CVE-2026-92815High· 7.5changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses53CVE-2026-95656High· 7.3A vulnerability was found in dgtlmoon changedetection.io up to 50389b0752CVE-2026-95271High· 7.3A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.752CVE-2026-95273Medium· 4.3A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.736CVE-2026-92814Medium· 4.2changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection35
dgtlmoon vulnerabilities
CVEs affecting dgtlmoon, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-95656High· 7.3PoCA vulnerability was found in dgtlmoon changedetection.io up to 50389b07
A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Pe…
CVE-2026-95657Low· 3.5A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8
A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a m…
CVE-2026-95271High· 7.3PoCA vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7
A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation lead…
CVE-2026-95272Low· 3.7PoCA vulnerability was found in dgtlmoon changedetection.io up to 0.60.7
A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument fil…
CVE-2026-95273Medium· 4.3PoCA vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7
A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argume…
CVE-2026-95270Low· 3.7PoCA flaw has been found in dgtlmoon changedetection.io up to 0.60.7
A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Passwor…
CVE-2026-92814Medium· 4.2PoCchangedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like em…
CVE-2026-92815High· 7.5PoCchangedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to re…