CVE-2026-29038 | dgtlmoon changedetection.io up to 0.54.3 HTTP Response /rss/tag/ cross site scripting (GHSA-8whx-v8qq-pq64)
A vulnerability labeled as problematic has been found in dgtlmoon changedetection.io up to 0.54.3. The impacted element is an unknown function of the file /rss/tag/ of the component HTTP Response Handler. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-29038. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.