No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | dgtlmoon changedetection.io visual_selector_data flask_app.py static_content path traversal | |
| First Time appeared |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:dgtlmoon:changedetection.io:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-22T14:35:23.321Z
Reserved: 2026-09-22T05:03:01.899Z
Link: CVE-2026-95273
No data.
Status : Received
Published: 2026-09-22T13:17:13.123
Modified: 2026-09-22T15:17:24.770
Link: CVE-2026-95273
No data.
OpenCVE Enrichment
Updated: 2026-09-22T16:00:15Z