Reflected XSS Vulnerability in Changedetection.io Tool
CVE-2026-29038

6.1MEDIUM

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
6 March 2026

What is CVE-2026-29038?

Changedetection.io is a popular open-source web page change detection tool, and it has been found to have a reflected cross-site scripting (XSS) vulnerability in its /rss/tag/ endpoint. Prior to the release of version 0.54.4, a flaw existed where the tag_uuid path parameter was directly reflected in the HTTP response without adequate HTML escaping. Consequently, this weakness allowed an attacker to inject malicious JavaScript that could be executed by the browser when users accessed the affected endpoint. The vulnerability has been addressed in version 0.54.4, where appropriate security measures have been implemented to mitigate this risk.

Affected Version(s)

changedetection.io < 0.54.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.