CVE-2026-95657
Last modified
CVE-2026-95657 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector.
Description
A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a manipulation of the argument s can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.60.1 is capable of addressing this issue. This patch is called aac6fcfa594f17511b8ff73e5eaa4f6c33899de0. It is suggested to upgrade the affected component.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| dgtlmoon | Changedetection.io | 0.55.0; 0.55.1; 0.55.2; 0.55.3; 0.55.4; 0.55.5; 0.55.6; 0.55.7; 0.55.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-95657?
How severe is CVE-2026-95657?
How do I fix CVE-2026-95657?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9564A vulnerability was found in SourceCodester/oretnom23 Hospit…2.4
- CVE-2026-9565A vulnerability was determined in haojing8312 WorkClaw up to…6.3
- CVE-2026-95653Concrete CMS Community Store before 2.7.8 derives digital pr…7.5
- CVE-2026-95654Databasement before 1.7.14 validates invitation tokens only …7.4
- CVE-2026-95655Aureus ERP before 1.5.0 fails to scope message lookups to th…8.1
- CVE-2026-95656A vulnerability was found in dgtlmoon changedetection.io up …7.3
- CVE-2026-95658MISP's WorkflowsController exposed the moduleStatelessExecut…6.9
- CVE-2026-95659MISP contains a reflected cross-site scripting (XSS) vulnera…4.8
- CVE-2026-9566A vulnerability was identified in teableio teable up to 1.9.…4.3
- CVE-2026-95660A security flaw has been discovered in Moonshot AI Kimi Code…6.3
- CVE-2026-95661MISP contains a reflected cross-site scripting (XSS) vulnera…5.1
- CVE-2026-95665MISP contains a reflected cross-site scripting (XSS) vulnera…5.1
Are you affected by CVE-2026-95657?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
