changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered resulting in a cross-site scripting (XSS) vulnerability. This issue has been patched in version 0.50.4
History

Tue, 24 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Jun 2025 21:00:00 +0000

Type Values Removed Values Added
Description changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered resulting in a cross-site scripting (XSS) vulnerability. This issue has been patched in version 0.50.4
Title ChangeDetection.io XSS in watch overview
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-23T20:52:24.343Z

Updated: 2025-06-24T17:18:38.374Z

Reserved: 2025-06-18T03:55:52.035Z

Link: CVE-2025-52558

cve-icon Vulnrichment

Updated: 2025-06-24T17:18:22.807Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-23T21:15:26.423

Modified: 2025-06-26T18:58:14.280

Link: CVE-2025-52558

cve-icon Redhat

No data.