S4E just found a low-severity finding from missing http security headers implementation scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2024-32651

10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
changedetection.io
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE history: changedetection.io

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →