Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates. | |
| Title | changedetection.io through 0.60.6 Cross-Site Scripting via watch_title | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T21:02:00.350Z
Reserved: 2026-09-16T19:55:02.492Z
Link: CVE-2026-92814
No data.
Status : Received
Published: 2026-09-16T21:17:31.343
Modified: 2026-09-16T21:17:31.343
Link: CVE-2026-92814
No data.
OpenCVE Enrichment
No data.