Vulnerabilities > Htmly > Htmly > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-31 CVE-2021-42867 Cross-site Scripting vulnerability in Htmly 2.8.1
A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.
network
low complexity
htmly CWE-79
4.8
2022-03-31 CVE-2021-42946 Cross-site Scripting vulnerability in Htmly 2.8.1
A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.
network
low complexity
htmly CWE-79
4.8
2022-03-29 CVE-2022-1087 Cross-site Scripting vulnerability in Htmly
A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profile Module.
network
low complexity
htmly CWE-79
5.4
2022-03-01 CVE-2022-25022 Cross-site Scripting vulnerability in Htmly 2.8.1
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
network
low complexity
htmly CWE-79
5.4
2021-08-03 CVE-2021-36702 Cross-site Scripting vulnerability in Htmly 2.8.1
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability.
network
low complexity
htmly CWE-79
6.1
2021-08-03 CVE-2021-36703 Cross-site Scripting vulnerability in Htmly 2.8.1
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability.
network
low complexity
htmly CWE-79
6.1
2021-05-21 CVE-2020-23766 Path Traversal vulnerability in Htmly 2.7.5
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
network
low complexity
htmly CWE-22
6.5
2021-04-13 CVE-2021-30637 Cross-site Scripting vulnerability in Htmly 2.8.0
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
network
low complexity
htmly CWE-79
5.4
2019-05-08 CVE-2019-8349 Cross-site Scripting vulnerability in Htmly 2.7.4
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.
network
low complexity
htmly CWE-79
6.1