Hexo records
3 published records for vendor hexo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-39584No exploit | Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.hexo · hexo · CWE-22 | High7.5 | — | 34.5% | Sep 8, 2023 |
39Monitor | CVE-2023-47435No exploit | An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected CWE-294 | Critical9.8 | — | 0.6% | Apr 19, 2024 |
18Monitor | CVE-2021-25987No exploit | Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS.hexo · hexo · CWE-79 | Medium4.6 | — | 0.3% | Nov 30, 2021 |
- CVE-2023-3958440Plan
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
HighCVSS 7.5No exploitEPSS 35%hexo · hexoSep 8, 2023
- CVE-2023-4743539Monitor
An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected
CriticalCVSS 9.8No exploitEPSS 1%Apr 19, 2024
- CVE-2021-2598718Monitor
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS.
MediumCVSS 4.6No exploitEPSS 0%hexo · hexoNov 30, 2021