Skip to content
Noroxi

htmly records

16 published records for vendor htmly.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

16 records
  • In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.

    CriticalCVSS 9.1No exploitEPSS 2%

    htmly · htmlyAug 3, 2021

  • Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parame

    HighCVSS 8.1No exploitEPSS 2%

    htmly · htmlySep 30, 2022

  • htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

    HighCVSS 8.1No exploitEPSS 1%

    htmly · htmlyAug 26, 2022

  • An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any

    MediumCVSS 6.5No exploitEPSS 1%

    htmly · htmlyMay 21, 2021

  • htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.

    MediumCVSS 6.5No exploitEPSS 1%

    htmly · htmlyMay 14, 2024

  • CVE-2019-8349
    25Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)

    MediumCVSS 6.1No exploitEPSS 2%

    htmly · htmlyMay 8, 2019

  • The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    htmly · htmlyAug 3, 2021

  • The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabi

    MediumCVSS 6.1No exploitEPSS 1%

    htmly · htmlyAug 3, 2021

  • A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pa

    MediumCVSS 6.1No exploitEPSS 0%

    htmly · htmlyApr 17, 2024

  • htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.

    MediumCVSS 6.1No exploitEPSS 0%

    htmly · htmlyOct 2, 2025

  • htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.

    MediumCVSS 5.4Proof of conceptEPSS 2%

    htmly · htmlyApr 13, 2021

  • A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in th

    MediumCVSS 5.4Proof of conceptEPSS 1%

    htmly · htmlyFeb 28, 2022

  • CVE-2022-1087
    21Monitor

    htmly Edit Profile Module cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    htmly · htmlyMar 29, 2022

  • A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pa

    MediumCVSS 4.8No exploitEPSS 1%

    htmly · htmlyMar 31, 2022

  • A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

    MediumCVSS 4.8No exploitEPSS 1%

    htmly · htmlyMar 31, 2022

  • htmly Custom Field post cross site scripting

    LowCVSS 1.9No exploitEPSS 0%

    htmly · htmlySep 20, 2025