Skip to content

Known CVE

ChangeDetection.io <= v0.50.33 - Stored XSS via Watch API

changedetection.io <= 0.50.34 contains a stored cross site scripting caused by insufficient security checks in the Watch update API, letting attackers execute arbitrary JavaScript when users preview malicious links, exploit requires user interaction

CVE-2025-62780

Medium2025CVSS 6.2CWE-79

cve2025 · changedetection · xss · stored · api

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website