Cross-Site Scripting in changedetection.io by dgtlmoon
CVE-2026-27645

6.1MEDIUM

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
25 February 2026

What is CVE-2026-27645?

changedetection.io is an open-source tool designed for monitoring changes in web pages. Prior to version 0.54.1, it was found to expose a cross-site scripting vulnerability through its RSS single-watch endpoint. This vulnerability arises because the application reflects the UUID path parameter directly in the HTTP response body without proper HTML escaping. As a result, it allows attackers to inject malicious JavaScript code into the response, which can be executed by the user's browser, potentially leading to unauthorized actions or data access. Users are advised to upgrade to version 0.54.1 or later to mitigate this risk.

Affected Version(s)

changedetection.io < 0.54.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.