CVE-2026-71204: Dgtlmoon Changedetection.io
Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.
Affected products
- Dgtlmoon Changedetection.io: version 0.55.7 only
Published 2026-08-05. Last modified 2026-08-28.