PT-2026-94086 · Dgtlmoon+1 · Changedetection.Io
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
changedetection.io versions prior to 0.60.7
Description
Failure to escape the scraped page title in HTML notifications allows arbitrary markup injection. When the
watch title token is used in templates, malicious markup placed in monitored page titles is delivered as live content to notification channels such as email and Telegram.Recommendations
Update changedetection.io to version 0.60.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Changedetection.Io