Description
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates.
Published: 2026-09-16
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross-site scripting via unsanitized watched page titles
Action: Patch
AI Analysis

Impact

The affected application, changedetection.io versions up to 0.60.6, contains a stored cross-site scripting vulnerability. A watched page title is rendered into HTML notifications without escaping, so an attacker can inject arbitrary markup into the watch_title token that appears in notification templates. If the notification is sent to channels that render HTML, such as email or Telegram, the injected markup can execute scripts or otherwise damage the experience of recipients. The consequence is a compromise of confidentiality and integrity for anyone receiving the notification, and the weakness is identified as CWE‑79.

Affected Systems

The vulnerability exists in changedetection.io, a web-based monitoring tool published by dgtlmoon. Versions up to and including 0.60.6 are impacted. Newer versions are not indicated as vulnerable.

Risk and Exploitability

With a CVSS score of 2.3 the severity is low, and the EPSS score of less than 1 % combined with the absence of a KEV listing suggests that exploitation is currently unlikely. The likely attack vector involves the attacker supplying a monitored page with a malicious title, or otherwise manipulating the watch_title field that is inserted into the notification template. If successful, the attacker can deliver malicious content to users who view the notification, potentially compromising their browsers or triggering unauthorized actions. The environment therefore poses low but real risk if the monitoring settings can be controlled by attackers.

Generated by OpenCVE AI on September 18, 2026 at 05:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to changedetection.io 0.60.7 or later to remove the unsanitized title handling,
  • Remove the watch_title token from notification templates or replace it with a safely escaped variant.
  • Restrict monitored pages to trusted sources or employ server-side validation to sanitize titles before they reach the template engine.

Generated by OpenCVE AI on September 18, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Dgtlmoon
Dgtlmoon changedetection.io
Vendors & Products Dgtlmoon
Dgtlmoon changedetection.io

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates.
Title changedetection.io through 0.60.6 Cross-Site Scripting via watch_title
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dgtlmoon Changedetection.io
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:24:11.367Z

Reserved: 2026-09-16T19:55:02.492Z

Link: CVE-2026-92814

cve-icon Vulnrichment

Updated: 2026-09-17T18:41:28.134Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:31.343

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')