Логотип exploitDog
bind:CVE-2025-56154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-56154

Количество 2

Количество 2

nvd логотип

CVE-2025-56154

4 месяца назад

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4xvq-93jj-7c4r

4 месяца назад

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-56154

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-4xvq-93jj-7c4r

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

CVSS3: 6.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу