changedetection.io <= 0.52.9 - Unauthenticated Path Traversal
changedetection.io / route, letting unauthenticated attackers read local application source files. References: https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-9jj8-v89v-xjvw https://nvd.nist.gov/vuln/detail/CVE-2026-25527 Remediation: Upgrade to version 0.53.2 or later.
Used 2.7k times · domain, subdomain, ipv4