changedetection.io <= 0.50.34 contains a stored cross site scripting caused by insufficient security checks in the Watch update API, letting attackers execute arbitrary JavaScript when users preview malicious links, exploit requires user interaction
id: CVE-2025-62780
info:
name: ChangeDetection.io <= v0.50.33 - Stored XSS via Watch API
author
...