CVE-2025-52558

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered resulting in a cross-site scripting (XSS) vulnerability. This issue has been patched in version 0.50.4
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) changedetection.io es un servicio gratuito de código abierto que detecta cambios en páginas web, vigila sitios web, monitoriza reabastecimiento y notifica. Antes de la versión 0.50.4, los errores en los filtros de los vigilantes de detección de cambios en páginas web no se filtraban, lo que provocaba una vulnerabilidad de cross-site scripting (XSS). Este problema se ha corregido en la versión 0.50.4.

23 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-23 21:15

Updated : 2025-06-26 18:58


NVD link : CVE-2025-52558

Mitre link : CVE-2025-52558

CVE.ORG link : CVE-2025-52558


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')