webtechnologies records
13 published records for vendor webtechnologies.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-863 Incorrect Authorization2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-73 External Control of File Name or Path1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-184 Incomplete List of Disallowed Inputs1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-35490No exploit | changedetection.io has an Authentication Bypass via Decorator Orderingwebtechnologies · changedetection · CWE-863 | Critical9.8 | — | 0.6% | Apr 7, 2026 |
35Monitor | CVE-2026-29065No exploit | changedetection.io: Zip Slip vulnerability in the backup restore functionalitywebtechnologies · changedetection · CWE-22 | High8.8 | — | 0.6% | Mar 6, 2026 |
35Monitor | CVE-2026-29039No exploit | changedetection.io: XPath - Arbitrary File Read via unparsed-text()webtechnologies · changedetection · CWE-94 | High8.8 | — | 0.5% | Mar 6, 2026 |
34Monitor | CVE-2026-27696No exploit | changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLswebtechnologies · changedetection · CWE-918 | High8.6 | — | 0.5% | Feb 25, 2026 |
33Monitor | CVE-2026-33981No exploit | Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filterswebtechnologies · changedetection · CWE-200 | High8.3 | — | 0.5% | Mar 27, 2026 |
32Monitor | CVE-2026-41895No exploit | changedetection.io: XXE vulnerability in the changedetection.io projectwebtechnologies · changedetection · CWE-611 | High8.2 | — | 0.4% | May 12, 2026 |
30Monitor | CVE-2026-43891No exploit | changedetection.io: Arbitrary Local File Read via crafted backup restorewebtechnologies · changedetection · CWE-73 | High7.5 | — | 0.5% | May 12, 2026 |
28Monitor | CVE-2026-35000No exploit | ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Readwebtechnologies · changedetection · CWE-184 | High7.1 | — | 0.5% | Apr 1, 2026 |
24Monitor | CVE-2026-27645Proof of concept | changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Responsewebtechnologies · changedetection · CWE-79 | Medium6.1 | — | 0.5% | Feb 25, 2026 |
24Monitor | CVE-2026-29038No exploit | changedetection.io: Reflected XSS in RSS Tag Error Responsewebtechnologies · changedetection · CWE-79 | Medium6.1 | — | 0.3% | Mar 6, 2026 |
21Monitor | CVE-2026-25527Proof of concept | changedetection.io vulnerable to unauthenticated static path traversalwebtechnologies · changedetection · CWE-22 | Medium5.3 | — | 0.9% | Feb 19, 2026 |
21Monitor | CVE-2023-24769No exploit | Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page.webtechnologies · changedetection · CWE-79 | Medium5.4 | — | 0.6% | Feb 17, 2023 |
14Monitor | CVE-2024-23329No exploit | changedetection.io API endpoint is not secured with API tokenwebtechnologies · changedetection · CWE-863 | Low3.7 | — | 0.6% | Jan 19, 2024 |
- CVE-2026-3549039Monitor
changedetection.io has an Authentication Bypass via Decorator Ordering
CriticalCVSS 9.8No exploitEPSS 1%webtechnologies · changedetectionApr 7, 2026
- CVE-2026-2906535Monitor
changedetection.io: Zip Slip vulnerability in the backup restore functionality
HighCVSS 8.8No exploitEPSS 1%webtechnologies · changedetectionMar 6, 2026
- CVE-2026-2903935Monitor
changedetection.io: XPath - Arbitrary File Read via unparsed-text()
HighCVSS 8.8No exploitEPSS 1%webtechnologies · changedetectionMar 6, 2026
- CVE-2026-2769634Monitor
changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs
HighCVSS 8.6No exploitEPSS 0%webtechnologies · changedetectionFeb 25, 2026
- CVE-2026-3398133Monitor
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
HighCVSS 8.3No exploitEPSS 0%webtechnologies · changedetectionMar 27, 2026
- CVE-2026-4189532Monitor
changedetection.io: XXE vulnerability in the changedetection.io project
HighCVSS 8.2No exploitEPSS 0%webtechnologies · changedetectionMay 12, 2026
- CVE-2026-4389130Monitor
changedetection.io: Arbitrary Local File Read via crafted backup restore
HighCVSS 7.5No exploitEPSS 0%webtechnologies · changedetectionMay 12, 2026
- CVE-2026-3500028Monitor
ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read
HighCVSS 7.1No exploitEPSS 0%webtechnologies · changedetectionApr 1, 2026
- CVE-2026-2764524Monitor
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
MediumCVSS 6.1Proof of conceptEPSS 0%webtechnologies · changedetectionFeb 25, 2026
- CVE-2026-2903824Monitor
changedetection.io: Reflected XSS in RSS Tag Error Response
MediumCVSS 6.1No exploitEPSS 0%webtechnologies · changedetectionMar 6, 2026
- CVE-2026-2552721Monitor
changedetection.io vulnerable to unauthenticated static path traversal
MediumCVSS 5.3Proof of conceptEPSS 1%webtechnologies · changedetectionFeb 19, 2026
- CVE-2023-2476921Monitor
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page.
MediumCVSS 5.4No exploitEPSS 1%webtechnologies · changedetectionFeb 17, 2023
- CVE-2024-2332914Monitor
changedetection.io API endpoint is not secured with API token
LowCVSS 3.7No exploitEPSS 1%webtechnologies · changedetectionJan 19, 2024