Skip to content

Known CVE

changedetection.io <= 0.52.9 - Unauthenticated Path Traversal

changedetection.io <= 0.53.9 contains a path traversal caused by improper validation of the 'group' parameter in /static/<group>/<filename> route, letting unauthenticated attackers read local application source files.

CVE-2026-25527

Medium2026CVSS 5.3CWE-22

cve2026 · changedetection · lfi · traversal · unauth · exposure

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website