Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-62780

30
FAUCET Score

CVE-2025-62780 describes a Stored Cross-Site Scripting (XSS) vulnerability in changedetection.io versions prior to 0.50.34. This flaw allows an authenticated attacker to inject malicious JavaScript payloads through the Watch update API, either by manipulating a new watch's URL or by substituting an existing watch's URL. The vulnerability is rated Medium severity (CVSS 5.4), requiring user interaction (clicking a malicious link) for successful exploitation, and could lead to limited confidentiality and integrity impacts. While there are no known public exploits or Metasploit/ExploitDB modules, a recent community post on Bluesky incorrectly claims Nuclei exploit code exists. The vulnerability has garnered minimal community discussion and no media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.50.34CPE matchmatch criteria
cpe:2.3:a:changedetection:changedetection:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.5LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
0.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
36.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-62780 · Feb 23, 2026
This CVE's current EPSS score of 0.0044 is in the 54th percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: changedetection.ioFixed in: 0.50.34
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-4c3j-3h7v-22q9low

changedetection.io: Stored XSS in Watch update via API

Nov 12, 2025

References

github.com / dgtlmoon/changedetection.io/security/advisories/GHSA-4c3j-3h7v-22q9
ExploitVendor Advisory