pypi

changedetection-io

View on pypi registry
39 Total advisories
39 Vulnerabilities
0 Malware

Dependency scanning

Check whether changedetection-io is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.6
PyPI

CVE-2024-56509

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

CRITICAL 10.0
PyPI

CVE-2024-32651

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

LOW 3.7
PyPI

CVE-2024-23329

changedetection.io API endpoint is not secured with API token

MEDIUM 4.3
PyPI

CVE-2024-34061

changedetection.io Cross-site Scripting vulnerability

MEDIUM 5.3
PyPI

CVE-2026-25527

changedetection.io is vulnerable to unauthenticated static path traversal

CRITICAL 10.0
PyPI

CVE-2024-32651

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

HIGH 8.6
PyPI

CVE-2026-27696

changedetection.io is Vulnerable to SSRF via Watch URLs

UNKNOWN
PyPI

CVE-2026-29039

changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()

MEDIUM 6.1
PyPI

CVE-2026-29038

changedetection.io has Reflected XSS in its RSS Tag Error Response

UNKNOWN
PyPI

CVE-2026-29065

changedetection.io has Zip Slip vulnerability in the backup restore functionality

UNKNOWN
PyPI

CVE-2026-33981

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

MEDIUM 6.1
PyPI

CVE-2026-27645

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

MEDIUM 6.1
PyPI

CVE-2026-29038

CVE-2026-29038

HIGH 7.5
PyPI

CVE-2026-29039

CVE-2026-29039

UNKNOWN
PyPI

CVE-2026-35000

CVE-2026-35000

MEDIUM 6.1
PyPI

CVE-2026-27645

CVE-2026-27645

CRITICAL 9.1
PyPI

CVE-2026-29065

CVE-2026-29065

MEDIUM 6.5
PyPI

CVE-2026-33981

CVE-2026-33981

HIGH 8.6
PyPI

CVE-2026-27696

CVE-2026-27696

MEDIUM 5.3
PyPI

CVE-2026-25527

CVE-2026-25527

HIGH 7.5
PyPI

CVE-2026-43891

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

MEDIUM 6.5
PyPI

CVE-2024-51483

changedetection.io Path Traversal

HIGH 8.6
PyPI

CVE-2024-51998

changedetection.io path traversal using file URI scheme without supplying hostname

UNKNOWN
PyPI

CVE-2025-52558

ChangeDetection.io XSS in watch overview

MEDIUM 4.3
PyPI

CVE-2024-34061

changedetection.io Cross-site Scripting vulnerability

HIGH 8.6
PyPI

CVE-2024-56509

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

UNKNOWN
PyPI

CVE-2025-52558

ChangeDetection.io XSS in watch overview

MEDIUM 6.5
PyPI

CVE-2024-51483

changedetection.io Path Traversal

HIGH 8.6
PyPI

CVE-2024-51998

changedetection.io path traversal using file URI scheme without supplying hostname

HIGH 7.5
PyPI

CVE-2026-43891

CVE-2026-43891

UNKNOWN
PyPI

CVE-2023-24769

CVE-2023-24769

HIGH 7.5
PyPI

CVE-2026-41895

changedetection.io project has an XXE vulnerability

LOW 3.5
PyPI

CVE-2025-62780

changedetection.io: Stored XSS in Watch update via API

CRITICAL 9.8
PyPI

CVE-2026-35490

changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering

HIGH 7.5
PyPI

CVE-2026-41895

CVE-2026-41895

CRITICAL 9.8
PyPI

CVE-2026-35490

CVE-2026-35490

MEDIUM 5.4
PyPI

CVE-2025-62780

CVE-2025-62780

MEDIUM 5.4
PyPI

CVE-2023-24769

Stored cross site scripting in changedetection.io

LOW 3.7
PyPI

CVE-2024-23329

CVE-2024-23329

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes