pkg:PyPI/changedetection-io
24 total CVEsCRITICAL3HIGH7MEDIUM6LOW4
✅ Check your installed version
All known vulnerabilities
- CRITICAL10.0CVE-2024-32651changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Executionfrom 0, < 0.45.21
- CRITICAL9.8CVE-2026-35490changedetection.io Vulnerable to Authentication Bypass via Decorator Orderingfrom 0, < 0.54.8
- CRITICAL9.8CVE-2026-35490changedetection.io Vulnerable to Authentication Bypass via Decorator Orderingfrom 0, < 0.54.8
- from 0, < 0.54.1
- HIGH8.6CVE-2024-56509changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversalfrom 0, < 0.48.05
- HIGH8.6CVE-2024-51998changedetection.io path traversal using file URI scheme without supplying hostnamefrom 0, < 0.47.6
- HIGH7.5CVE-2026-43891changedetection.io has an Arbitrary Local File Read via a crafted backup restorefrom 0, < 0.55.1
- HIGH7.5CVE-2026-43891changedetection.io has an Arbitrary Local File Read via a crafted backup restorefrom 0, < 0.55.1
- from 0, <= 0.54.9
- from 0, < 0.54.10
- from 0, < 0.47.5
- from 0, < 0.54.4
- MEDIUM6.1CVE-2026-27645changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Responsefrom 0, < 0.53.7
- from 0, < 0.40.2
- from 0, < 0.40.1.1
- from 0, < 0.45.22
- >= 0.39.14, < 0.45.13
- from 0, < 402f1e47e78ecd155b1e90f30cce424ff7763e0f | >= 0.39.14, < 0.45.13
- from 0, < 0.50.34
- from 0, < 0.50.34
- —CVE-2026-33981Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filtersfrom 0, < 0.54.7
- from 0, < 0.54.4
- from 0, < 0.54.4
- from 0, < 0.50.4