Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | dgtlmoon changedetection.io visual_selector_data flask_app.py static_content path traversal | |
| First Time appeared |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:dgtlmoon:changedetection.io:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-22T14:35:23.321Z
Reserved: 2026-09-22T05:03:01.899Z
Link: CVE-2026-95273
No data.
Status : Received
Published: 2026-09-22T13:17:13.123
Modified: 2026-09-22T13:17:13.123
Link: CVE-2026-95273
No data.
OpenCVE Enrichment
Updated: 2026-09-22T14:00:19Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')