Skip to content
Noroxi

webtechnologies records

13 published records for vendor webtechnologies.

All records

13 records
  • changedetection.io has an Authentication Bypass via Decorator Ordering

    CriticalCVSS 9.8No exploitEPSS 1%

    webtechnologies · changedetectionApr 7, 2026

  • changedetection.io: Zip Slip vulnerability in the backup restore functionality

    HighCVSS 8.8No exploitEPSS 1%

    webtechnologies · changedetectionMar 6, 2026

  • changedetection.io: XPath - Arbitrary File Read via unparsed-text()

    HighCVSS 8.8No exploitEPSS 1%

    webtechnologies · changedetectionMar 6, 2026

  • changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs

    HighCVSS 8.6No exploitEPSS 0%

    webtechnologies · changedetectionFeb 25, 2026

  • Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

    HighCVSS 8.3No exploitEPSS 0%

    webtechnologies · changedetectionMar 27, 2026

  • changedetection.io: XXE vulnerability in the changedetection.io project

    HighCVSS 8.2No exploitEPSS 0%

    webtechnologies · changedetectionMay 12, 2026

  • changedetection.io: Arbitrary Local File Read via crafted backup restore

    HighCVSS 7.5No exploitEPSS 0%

    webtechnologies · changedetectionMay 12, 2026

  • ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read

    HighCVSS 7.1No exploitEPSS 0%

    webtechnologies · changedetectionApr 1, 2026

  • changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

    MediumCVSS 6.1Proof of conceptEPSS 0%

    webtechnologies · changedetectionFeb 25, 2026

  • changedetection.io: Reflected XSS in RSS Tag Error Response

    MediumCVSS 6.1No exploitEPSS 0%

    webtechnologies · changedetectionMar 6, 2026

  • changedetection.io vulnerable to unauthenticated static path traversal

    MediumCVSS 5.3Proof of conceptEPSS 1%

    webtechnologies · changedetectionFeb 19, 2026

  • Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page.

    MediumCVSS 5.4No exploitEPSS 1%

    webtechnologies · changedetectionFeb 17, 2023

  • changedetection.io API endpoint is not secured with API token

    LowCVSS 3.7No exploitEPSS 1%

    webtechnologies · changedetectionJan 19, 2024