Webtechnologies maintains a narrowly scoped product portfolio centered on the changedetection monitoring and alerting application, which serves web-tracking and automation use cases and holds a prominent position within its niche. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, clustering around web-application weaknesses including cross-site scripting, path traversal, improper authorization, sensitive-information disclosure, and external path control that reflect the dangers of parsing and validating untrusted input in web-facing services. Defenders should monitor this vendor's releases closely and treat exposed instances as requiring prompt remediation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webtechnologies over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35490CRITICAL changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() in | Apr 7, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-27645MEDIUM changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the | Feb 25, 2026 | 6.1 | 33 | NO | YES |
CVE-2026-29065CRITICAL changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file | Mar 6, 2026 | 9.1 | 29 | NO | NO |
CVE-2026-25527MEDIUM changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `sen | Feb 19, 2026 | 5.3 | 29 | NO | YES |
CVE-2026-43891HIGH changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from b | May 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-41895HIGH changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser( | May 12, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-27696HIGH changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because | Feb 25, 2026 | 8.6 | 26 | NO | NO |
CVE-2026-29039HIGH changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as co | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-35000MEDIUM ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by | Apr 1, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-33981MEDIUM changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which | Mar 27, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webtechnologies.
Media articles that mention a CVE ID that affects a product developed by Webtechnologies — matched by CVE ID, not by vendor name.