VYPR

Hexo

by Hexo

Source repositories

CVEs (1)

  • CVE-2021-25987Nov 30, 2021
    risk 0.00cvss epss 0.00

    Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.