CVE-2026-95657 Details
Description
A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a manipulation of the argument s can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.60.1 is capable of addressing this issue. This patch is called aac6fcfa594f17511b8ff73e5eaa4f6c33899de0. It is suggested to upgrade the affected component.
A cross-site scripting (XSS) vulnerability has been identified in Changedetection.io versions through 0.55.8. The issue arises in the Visual Selector component, specifically within the 'setCurrentSelectedText' function of 'changedetectionio/static/js/visual-selector.js'. This vulnerability allows for the injection of malicious XPath strings, which are then executed as HTML, creating a DOM-based XSS risk. The vulnerability can be exploited remotely by manipulating the XPath data of monitored pages.
Users are advised to upgrade to Changedetection.io version 0.60.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dgtlmoon/changedetection.io/ | [email protected] | Vendor |
| https://github.com/dgtlmoon/changedetection.io/commit/aac6fcfa594f17511b8ff73e5eaa4f6c33899de0 | [email protected] | Source CodeVendor |
| https://github.com/dgtlmoon/changedetection.io/pull/4282 | [email protected] | Issue TrackingVendor |
| https://github.com/dgtlmoon/changedetection.io/releases/tag/0.60.1 | [email protected] | Release NotesVendor |
| https://github.com/herantong/cve/blob/main/changedetection.io_xss-visual-selector_CWE-79 | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-95657 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/896587 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408413 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408413/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dgtlmoon Changedetection.io | <= 0.55.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion