Changedetection
Vendor:
First CVE: Feb 17, 2023 · Active for 3 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Changedetection over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2023
3 years ago
Most Recent CVE
May 12, 2026
73 days ago
CVE Severity & Scoring
Changedetection13 CVEs
46%
31%
15%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low3 (23.1%)
High0 (0.0%)
None10 (76.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35490CRITICAL changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() in | Apr 7, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-27645MEDIUM changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the | Feb 25, 2026 | 6.1 | 33 | NO | YES |
CVE-2026-29065CRITICAL changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file | Mar 6, 2026 | 9.1 | 29 | NO | NO |
CVE-2026-25527MEDIUM changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `sen | Feb 19, 2026 | 5.3 | 29 | NO | YES |
CVE-2026-43891HIGH changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from b | May 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-41895HIGH changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser( | May 12, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-27696HIGH changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because | Feb 25, 2026 | 8.6 | 26 | NO | NO |
CVE-2026-29039HIGH changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as co | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-35000MEDIUM ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by | Apr 1, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-33981MEDIUM changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which | Mar 27, 2026 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
15.4% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Changedetection
Top CWEs
Versions
No cataloged versions.