Htmly / Htmly
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-56154 | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitize… | MEDIUM | 6.1 | Oct 2, 2025 |
| CVE-2025-10758 | htmly Custom Field post cross site scripting | MEDIUM | 4.8 | Sep 21, 2025 |
| CVE-2024-34191 | htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attacker… | MEDIUM | 6.5 | May 14, 2024 |
| CVE-2024-30953 | A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… | MEDIUM | 6.1 | Apr 17, 2024 |
| CVE-2021-33354 | Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter. | HIGH | 8.1 | Sep 30, 2022 |
| CVE-2021-40285 | htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php. | HIGH | 8.1 | Aug 26, 2022 |
| CVE-2021-42946 | A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page. | MEDIUM | 4.8 | Mar 31, 2022 |
| CVE-2021-42867 | A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages. | MEDIUM | 4.8 | Mar 31, 2022 |
| CVE-2022-1087 | htmly Edit Profile Module cross site scripting | MEDIUM | 5.4 | Mar 29, 2022 |
| CVE-2022-25022 | A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of… | MEDIUM | 5.4 | Mar 1, 2022 |
| CVE-2021-36703 | The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows rem… | MEDIUM | 6.1 | Aug 3, 2021 |
| CVE-2021-36702 | The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabilit… | MEDIUM | 6.1 | Aug 3, 2021 |
| CVE-2021-36701 | In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files. The vulnerability may allow a remote attacker t… | CRITICAL | 9.1 | Aug 3, 2021 |
| CVE-2020-23766 | An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server… | MEDIUM | 6.5 | May 21, 2021 |
| CVE-2021-30637 | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. | MEDIUM | 5.4 | Apr 13, 2021 |
| CVE-2019-8349 | Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parame… | MEDIUM | 6.1 | May 8, 2019 |
Showing 1 to 16 of 16 CVEs