VYPR
Medium severity6.1NVD Advisory· Published Aug 3, 2021· Updated Jun 17, 2026

CVE-2021-36702

CVE-2021-36702

Description

The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inject arbitrary web scripts or HTML through special content.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Danpros/Htmly2 versions
    cpe:2.3:a:htmly:htmly:2.8.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:htmly:htmly:2.8.1:*:*:*:*:*:*:*
    • (no CPE)range: =2.8.1
  • htmly/htmlydescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.