htmly records
16 published records for vendor htmly.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-35 Path Traversal: '.../...//'1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-36701No exploit | In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.htmly · htmly | Critical9.1 | — | 1.6% | Aug 3, 2021 |
32Monitor | CVE-2021-33354No exploit | Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file paramehtmly · htmly · CWE-22 | High8.1 | — | 1.5% | Sep 30, 2022 |
32Monitor | CVE-2021-40285No exploit | htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.htmly · htmly · CWE-22 | High8.1 | — | 1.0% | Aug 26, 2022 |
26Monitor | CVE-2020-23766No exploit | An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete anyhtmly · htmly · CWE-22 | Medium6.5 | — | 1.4% | May 21, 2021 |
26Monitor | CVE-2024-34191No exploit | htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.htmly · htmly · CWE-35 | Medium6.5 | — | 0.5% | May 14, 2024 |
25Monitor | CVE-2019-8349No exploit | Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)htmly · htmly · CWE-79 | Medium6.1 | — | 2.2% | May 8, 2019 |
24Monitor | CVE-2021-36702No exploit | The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scriptinghtmly · htmly · CWE-79 | Medium6.1 | — | 0.9% | Aug 3, 2021 |
24Monitor | CVE-2021-36703No exploit | The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabihtmly · htmly · CWE-79 | Medium6.1 | — | 0.9% | Aug 3, 2021 |
24Monitor | CVE-2024-30953No exploit | A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pahtmly · htmly · CWE-79 | Medium6.1 | — | 0.4% | Apr 17, 2024 |
24Monitor | CVE-2025-56154No exploit | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.htmly · htmly · CWE-79 | Medium6.1 | — | 0.3% | Oct 2, 2025 |
22Monitor | CVE-2021-30637Proof of concept | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.htmly · htmly · CWE-79 | Medium5.4 | — | 1.9% | Apr 13, 2021 |
21Monitor | CVE-2022-25022Proof of concept | A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in thhtmly · htmly · CWE-79 | Medium5.4 | — | 1.1% | Feb 28, 2022 |
21Monitor | CVE-2022-1087No exploit | htmly Edit Profile Module cross site scriptinghtmly · htmly · CWE-79 | Medium5.4 | — | 0.9% | Mar 29, 2022 |
19Monitor | CVE-2021-42867No exploit | A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pahtmly · htmly · CWE-79 | Medium4.8 | — | 0.6% | Mar 31, 2022 |
19Monitor | CVE-2021-42946No exploit | A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.htmly · htmly · CWE-79 | Medium4.8 | — | 0.6% | Mar 31, 2022 |
7Monitor | CVE-2025-10758No exploit | htmly Custom Field post cross site scriptinghtmly · htmly · CWE-79 | Low1.9 | — | 0.3% | Sep 20, 2025 |
- CVE-2021-3670136Monitor
In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.
CriticalCVSS 9.1No exploitEPSS 2%htmly · htmlyAug 3, 2021
- CVE-2021-3335432Monitor
Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parame
HighCVSS 8.1No exploitEPSS 2%htmly · htmlySep 30, 2022
- CVE-2021-4028532Monitor
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.
HighCVSS 8.1No exploitEPSS 1%htmly · htmlyAug 26, 2022
- CVE-2020-2376626Monitor
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any
MediumCVSS 6.5No exploitEPSS 1%htmly · htmlyMay 21, 2021
- CVE-2024-3419126Monitor
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.
MediumCVSS 6.5No exploitEPSS 1%htmly · htmlyMay 14, 2024
- CVE-2019-834925Monitor
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)
MediumCVSS 6.1No exploitEPSS 2%htmly · htmlyMay 8, 2019
- CVE-2021-3670224Monitor
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting
MediumCVSS 6.1No exploitEPSS 1%htmly · htmlyAug 3, 2021
- CVE-2021-3670324Monitor
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabi
MediumCVSS 6.1No exploitEPSS 1%htmly · htmlyAug 3, 2021
- CVE-2024-3095324Monitor
A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pa
MediumCVSS 6.1No exploitEPSS 0%htmly · htmlyApr 17, 2024
- CVE-2025-5615424Monitor
htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.
MediumCVSS 6.1No exploitEPSS 0%htmly · htmlyOct 2, 2025
- CVE-2021-3063722Monitor
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
MediumCVSS 5.4Proof of conceptEPSS 2%htmly · htmlyApr 13, 2021
- CVE-2022-2502221Monitor
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in th
MediumCVSS 5.4Proof of conceptEPSS 1%htmly · htmlyFeb 28, 2022
- CVE-2022-108721Monitor
htmly Edit Profile Module cross site scripting
MediumCVSS 5.4No exploitEPSS 1%htmly · htmlyMar 29, 2022
- CVE-2021-4286719Monitor
A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pa
MediumCVSS 4.8No exploitEPSS 1%htmly · htmlyMar 31, 2022
- CVE-2021-4294619Monitor
A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.
MediumCVSS 4.8No exploitEPSS 1%htmly · htmlyMar 31, 2022
- CVE-2025-107587Monitor
htmly Custom Field post cross site scripting
LowCVSS 1.9No exploitEPSS 0%htmly · htmlySep 20, 2025