Dependency scanning
Check whether changedetection-io is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-56509
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
CVE-2024-32651
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
CVE-2024-23329
changedetection.io API endpoint is not secured with API token
CVE-2024-34061
changedetection.io Cross-site Scripting vulnerability
CVE-2026-25527
changedetection.io is vulnerable to unauthenticated static path traversal
CVE-2024-32651
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
CVE-2026-27696
changedetection.io is Vulnerable to SSRF via Watch URLs
CVE-2026-29039
changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
CVE-2026-29038
changedetection.io has Reflected XSS in its RSS Tag Error Response
CVE-2026-29065
changedetection.io has Zip Slip vulnerability in the backup restore functionality
CVE-2026-33981
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
CVE-2026-27645
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
CVE-2026-29038
CVE-2026-29038
CVE-2026-29039
CVE-2026-29039
CVE-2026-35000
CVE-2026-35000
CVE-2026-27645
CVE-2026-27645
CVE-2026-29065
CVE-2026-29065
CVE-2026-33981
CVE-2026-33981
CVE-2026-27696
CVE-2026-27696
CVE-2026-25527
CVE-2026-25527
CVE-2026-43891
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
CVE-2024-51483
changedetection.io Path Traversal
CVE-2024-51998
changedetection.io path traversal using file URI scheme without supplying hostname
CVE-2025-52558
ChangeDetection.io XSS in watch overview
CVE-2024-34061
changedetection.io Cross-site Scripting vulnerability
CVE-2024-56509
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
CVE-2025-52558
ChangeDetection.io XSS in watch overview
CVE-2024-51483
changedetection.io Path Traversal
CVE-2024-51998
changedetection.io path traversal using file URI scheme without supplying hostname
CVE-2026-43891
CVE-2026-43891
CVE-2023-24769
CVE-2023-24769
CVE-2026-41895
changedetection.io project has an XXE vulnerability
CVE-2025-62780
changedetection.io: Stored XSS in Watch update via API
CVE-2026-35490
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering
CVE-2026-41895
CVE-2026-41895
CVE-2026-35490
CVE-2026-35490
CVE-2025-62780
CVE-2025-62780
CVE-2023-24769
Stored cross site scripting in changedetection.io
CVE-2024-23329
CVE-2024-23329
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes