CVE-2026-92814: changedetection.io through 0.60.6 Cross-Site Scripting via watch_title

Published Sep 16, 2026
·
Updated

changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watchtitle token is used in templates.

Affected Software

1 affected component
changedetection.io<=0.60.6

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users of changedetection.io through 0.60.6 are exposed when they monitor a page whose title an attacker can control and send HTML notifications using a template that includes the watch_title token. Notification recipients may receive the attacker-supplied markup as live content in channels such as email and Telegram.

2

What must an attacker do to exploit it?

An attacker needs to cause a monitored page to present a malicious title. When changedetection.io scrapes that title and a notification template uses watch_title, the title is inserted into the HTML notification without escaping.

3

Does this affect every changedetection.io notification setup?

The described injection path requires HTML notifications and use of the watch_title token in the notification template. The provided information does not establish impact for templates that do not include that token.

4

What can be done before an update is available?

Avoid using watch_title in HTML notification templates for watches of attacker-controlled or untrusted pages. Review notification templates and treat previously received HTML notifications containing scraped titles as potentially untrusted content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203