Medium severity6.1NVD Advisory· Published Mar 2, 2024· Updated Jun 17, 2026
CVE-2024-25865
CVE-2024-25865
Description
Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:anzhiyu-c:hexo-theme-anzhiyu:1.6.12:*:*:*:*:*:*:*
- hexo-theme-anzhiyu/anzhiyudescription
- ghsa-coords
Patches
Vulnerability mechanics
References
3- github.com/anzhiyu-c/hexo-theme-anzhiyu/issues/200nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-82jf-8f24-xq9mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-25865ghsaADVISORY
News mentions
0No linked articles in our index yet.