CVEFinder.io

CVE-2026-29065

⛔ critical
🔍 Scan for this CVE
Summary

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. This issue has been patched in version 0.54.4.

CVSS Score
9.1
Critical
EPSS Score
0.1
Exploit Probability
Published Date
2026-03-06
First Seen: 2026-03-07
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 87.7% of all 321,566 vulnerabilities in our database.

#39,677
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Mar 9, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-03-10
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-43891 ⚠️ high 7.5 0.0 changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by... 2026-05-12
CVE-2026-35490 ⛔ critical 9.8 0.0 changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required... 2026-04-07
CVE-2026-35000 🔶 medium 6.5 0.1 ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementa... 2026-04-01
CVE-2026-33981 🔶 medium 6.5 0.0 changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include... 2026-03-27
CVE-2026-29038 🔶 medium 6.1 0.0 changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c... 2026-03-06
CVE-2026-29039 ⚠️ high 7.5 0.0 changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io... 2026-03-06
These CVEs affect the same products