CVE-2026-71204: Dgtlmoon Changedetection.io

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

Affected products

  • Dgtlmoon Changedetection.io: version 0.55.7 only

Published 2026-08-05. Last modified 2026-08-28.