Launch Week Day 1: Announcing Security Design Review
pypi

changedetection-io

View on pypi registry
24 Total advisories
24 Vulnerabilities
0 Malware

Vulnerabilities

HIGH 7.5
PyPI

CVE-2026-43891

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

HIGH 7.5
PyPI

CVE-2026-43891

CVE-2026-43891

UNKNOWN
PyPI

CVE-2023-24769

CVE-2023-24769

HIGH 7.5
PyPI

CVE-2026-41895

changedetection.io project has an XXE vulnerability

LOW 3.5
PyPI

CVE-2025-62780

changedetection.io: Stored XSS in Watch update via API

CRITICAL 9.8
PyPI

CVE-2026-35490

changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering

HIGH 7.5
PyPI

CVE-2026-41895

CVE-2026-41895

CRITICAL 9.8
PyPI

CVE-2026-35490

CVE-2026-35490

MEDIUM 5.4
PyPI

CVE-2025-62780

CVE-2025-62780

UNKNOWN
PyPI

CVE-2026-33981

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

UNKNOWN
PyPI

CVE-2026-29039

changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()

MEDIUM 6.1
PyPI

CVE-2026-29038

changedetection.io has Reflected XSS in its RSS Tag Error Response

UNKNOWN
PyPI

CVE-2026-29065

changedetection.io has Zip Slip vulnerability in the backup restore functionality

MEDIUM 6.1
PyPI

CVE-2026-27645

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

HIGH 8.6
PyPI

CVE-2026-27696

changedetection.io is Vulnerable to SSRF via Watch URLs

CRITICAL 10.0
PyPI

CVE-2024-32651

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

UNKNOWN
PyPI

CVE-2025-52558

ChangeDetection.io XSS in watch overview

MEDIUM 5.4
PyPI

CVE-2023-24769

Stored cross site scripting in changedetection.io

HIGH 8.6
PyPI

CVE-2024-56509

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

HIGH 8.6
PyPI

CVE-2024-51998

changedetection.io path traversal using file URI scheme without supplying hostname

MEDIUM 6.5
PyPI

CVE-2024-51483

changedetection.io Path Traversal

LOW 3.7
PyPI

CVE-2024-23329

changedetection.io API endpoint is not secured with API token

MEDIUM 4.3
PyPI

CVE-2024-34061

changedetection.io Cross-site Scripting vulnerability

LOW 3.7
PyPI

CVE-2024-23329

CVE-2024-23329

Ready to move

Start Securing

Free, no credit card | First findings in minutes