PT-2026-94086 · Dgtlmoon+1 · Changedetection.Io

·

CVE-2026-92814

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions changedetection.io versions prior to 0.60.7
Description Failure to escape the scraped page title in HTML notifications allows arbitrary markup injection. When the watch title token is used in templates, malicious markup placed in monitored page titles is delivered as live content to notification channels such as email and Telegram.
Recommendations Update changedetection.io to version 0.60.7 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92814

Affected Products

Changedetection.Io