XML Parsing Vulnerability in Changedetection.io Web Page Monitoring Tool
CVE-2026-41895

8.2HIGH

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
12 May 2026

What is CVE-2026-41895?

Changedetection.io, a popular open-source web page change detection tool, is vulnerable due to improper handling of XML input. In versions prior to 0.54.9, the xpath_filter() function switches to XML mode without disabling critical security features such as external entity resolution and DTD loading. This vulnerability allows attackers to exploit the system by sending untrusted XML bytes to the parser, potentially leading to unauthorized access and data exposure. For more detailed information, refer to the security advisory.

Affected Version(s)

changedetection.io <= 0.54.9

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.