Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

dgtlmoon — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting dgtlmoon. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dgtlmoon develops digital asset management solutions primarily serving creative industries and content-heavy organizations. Historically, their products have been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for the majority of their 17 recorded CVEs. While no major public security incidents have been documented, their vulnerability history suggests consistent challenges in input validation and access control. The company's security posture has shown gradual improvement over time, with more recent releases addressing earlier patterns of insecure direct object references and insufficient session management.

Top products by dgtlmoon: changedetection.io
CVE ID Title CVSS Severity Published
CVE-2026-95657 dgtlmoon Changedetection.io Visual Selector visual-selector.js setCurrentSelectedText cross site scripting — Changedetection.io CWE-79 3.5 Low 2026-09-22
CVE-2026-95656 dgtlmoon changedetection.io Preview Endpoint __init__.py add_watch_ui_snapshot server-side request forgery — changedetection.io CWE-918 7.3 High 2026-09-22
CVE-2026-95273 dgtlmoon changedetection.io visual_selector_data flask_app.py static_content path traversal — changedetection.io CWE-22 4.3 Medium 2026-09-22
CVE-2026-95272 dgtlmoon changedetection.io Screenshot flask_app.py static_content path traversal — changedetection.io CWE-22 3.7 Low 2026-09-22
CVE-2026-95271 dgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authentication — changedetection.io CWE-287 7.3 High 2026-09-22
CVE-2026-95270 dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy — changedetection.io CWE-208 3.7 Low 2026-09-22
CVE-2026-92815 changedetection.io through 0.60.6 SSRF via browser-step Goto URL — changedetection.io CWE-918 7.5 High 2026-09-16
CVE-2026-92814 changedetection.io through 0.60.6 Cross-Site Scripting via watch_title — changedetection.io CWE-79 4.2 Medium 2026-09-16
CVE-2026-71205 changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force — changedetection.io CWE-307 6.5 Medium 2026-08-05
CVE-2026-71204 changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement — changedetection.io CWE-284 6.3 Medium 2026-08-05
CVE-2026-71203 changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema — changedetection.io CWE-306 5.3 Medium 2026-08-05
CVE-2026-43891 changedetection.io: Arbitrary Local File Read via crafted backup restore — changedetection.io CWE-73 7.5 High 2026-05-12
CVE-2026-41895 changedetection.io: XXE vulnerability in the changedetection.io project — changedetection.io CWE-611 - - 2026-05-12
CVE-2026-35490 changedetection.io has an Authentication Bypass via Decorator Ordering — changedetection.io CWE-863 9.8 Critical 2026-04-07
CVE-2026-35000 ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read — ChangeDetection.io CWE-184 6.5 Medium 2026-04-01
CVE-2026-33981 Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters — changedetection.io CWE-200 7.5 - 2026-03-27
CVE-2026-29065 changedetection.io: Zip Slip vulnerability in the backup restore functionality — changedetection.io CWE-22 6.5 - 2026-03-06
CVE-2026-29039 changedetection.io: XPath - Arbitrary File Read via unparsed-text() — changedetection.io CWE-94 6.5 - 2026-03-06
CVE-2026-29038 changedetection.io: Reflected XSS in RSS Tag Error Response — changedetection.io CWE-79 6.1 Medium 2026-03-06
CVE-2026-27696 changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs — changedetection.io CWE-918 8.6 High 2026-02-25
CVE-2026-27645 changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response — changedetection.io CWE-79 6.1 Medium 2026-02-25
CVE-2026-25527 changedetection.io vulnerable to unauthenticated static path traversal — changedetection.io CWE-22 5.3 Medium 2026-02-19
CVE-2025-62780 changedetection.io vulnerable to stored XSS in Watch update via API — changedetection.io CWE-79 3.5 Low 2025-11-10
CVE-2025-52558 ChangeDetection.io XSS in watch overview — changedetection.io CWE-79 5.4AI Medium AI 2025-06-23
CVE-2024-56509 changedetection.io has Improper Input Validation Leading to LFR/Path Traversal — changedetection.io CWE-200 8.6 High 2024-12-27
CVE-2024-51998 Path traversal using file URI scheme without supplying hostname in changedetection.io — changedetection.io CWE-22 8.6 High 2024-11-07
CVE-2024-51483 changedetection.io Path Traversal vulnerability — changedetection.io CWE-22 6.5AI Medium AI 2024-11-01
CVE-2024-34061 Reflected cross site scripting in changedetection.io — changedetection.io CWE-79 4.3 Medium 2024-05-02
CVE-2024-32651 Server Side Template Injection in Jinja2 allows Remote Command Execution — changedetection.io CWE-1336 10.0 Critical 2024-04-25
CVE-2024-23329 changedetection.io API endpoint is not secured with API token — changedetection.io CWE-863 3.7 Low 2024-01-19

This page lists every published CVE security advisory associated with dgtlmoon. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.