PT-2025-26644 · Unknown · Changedetection.Io

Dgtlmoon

·

Published

2025-06-23

·

Updated

2025-07-25

·

CVE-2025-52558

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: changedetection.io versions prior to 0.50.4
Description: The issue is related to a cross-site scripting (XSS) vulnerability due to errors in filters from website page change detection watches not being properly filtered. This vulnerability has been patched in version 0.50.4.
Recommendations: For versions prior to 0.50.4, update to version 0.50.4 to resolve the issue. As a temporary workaround, consider restricting access to the filter functionality until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52558
GHSA-HWPG-X5HW-VPV9

Affected Products

Changedetection.Io