Записи htmly
16 опубликованных записей вендора htmly.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-35 Path Traversal: '.../...//'1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-36701Эксплойта нет | In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.htmly · htmly | Критическая9,1 | — | 1,6 % | 3 авг. 2021 г. |
32Наблюдать | CVE-2021-33354Эксплойта нет | Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file paramehtmly · htmly · CWE-22 | Высокая8,1 | — | 1,5 % | 30 сент. 2022 г. |
32Наблюдать | CVE-2021-40285Эксплойта нет | htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.htmly · htmly · CWE-22 | Высокая8,1 | — | 1,0 % | 26 авг. 2022 г. |
26Наблюдать | CVE-2020-23766Эксплойта нет | An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete anyhtmly · htmly · CWE-22 | Средняя6,5 | — | 1,4 % | 21 мая 2021 г. |
26Наблюдать | CVE-2024-34191Эксплойта нет | htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.htmly · htmly · CWE-35 | Средняя6,5 | — | 0,5 % | 14 мая 2024 г. |
25Наблюдать | CVE-2019-8349Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)htmly · htmly · CWE-79 | Средняя6,1 | — | 2,2 % | 8 мая 2019 г. |
24Наблюдать | CVE-2021-36702Эксплойта нет | The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scriptinghtmly · htmly · CWE-79 | Средняя6,1 | — | 0,9 % | 3 авг. 2021 г. |
24Наблюдать | CVE-2021-36703Эксплойта нет | The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabihtmly · htmly · CWE-79 | Средняя6,1 | — | 0,9 % | 3 авг. 2021 г. |
24Наблюдать | CVE-2024-30953Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pahtmly · htmly · CWE-79 | Средняя6,1 | — | 0,4 % | 17 апр. 2024 г. |
24Наблюдать | CVE-2025-56154Эксплойта нет | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.htmly · htmly · CWE-79 | Средняя6,1 | — | 0,3 % | 2 окт. 2025 г. |
22Наблюдать | CVE-2021-30637Proof of concept | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.htmly · htmly · CWE-79 | Средняя5,4 | — | 1,9 % | 13 апр. 2021 г. |
21Наблюдать | CVE-2022-25022Proof of concept | A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in thhtmly · htmly · CWE-79 | Средняя5,4 | — | 1,1 % | 28 февр. 2022 г. |
21Наблюдать | CVE-2022-1087Эксплойта нет | htmly Edit Profile Module cross site scriptinghtmly · htmly · CWE-79 | Средняя5,4 | — | 0,9 % | 29 мар. 2022 г. |
19Наблюдать | CVE-2021-42867Эксплойта нет | A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pahtmly · htmly · CWE-79 | Средняя4,8 | — | 0,6 % | 31 мар. 2022 г. |
19Наблюдать | CVE-2021-42946Эксплойта нет | A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.htmly · htmly · CWE-79 | Средняя4,8 | — | 0,6 % | 31 мар. 2022 г. |
7Наблюдать | CVE-2025-10758Эксплойта нет | htmly Custom Field post cross site scriptinghtmly · htmly · CWE-79 | Низкая1,9 | — | 0,3 % | 20 сент. 2025 г. |
- CVE-2021-3670136Наблюдать
In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %htmly · htmly3 авг. 2021 г.
- CVE-2021-3335432Наблюдать
Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parame
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %htmly · htmly30 сент. 2022 г.
- CVE-2021-4028532Наблюдать
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %htmly · htmly26 авг. 2022 г.
- CVE-2020-2376626Наблюдать
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any
СредняяCVSS 6,5Эксплойта нетEPSS 1 %htmly · htmly21 мая 2021 г.
- CVE-2024-3419126Наблюдать
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %htmly · htmly14 мая 2024 г.
- CVE-2019-834925Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)
СредняяCVSS 6,1Эксплойта нетEPSS 2 %htmly · htmly8 мая 2019 г.
- CVE-2021-3670224Наблюдать
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %htmly · htmly3 авг. 2021 г.
- CVE-2021-3670324Наблюдать
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabi
СредняяCVSS 6,1Эксплойта нетEPSS 1 %htmly · htmly3 авг. 2021 г.
- CVE-2024-3095324Наблюдать
A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pa
СредняяCVSS 6,1Эксплойта нетEPSS 0 %htmly · htmly17 апр. 2024 г.
- CVE-2025-5615424Наблюдать
htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %htmly · htmly2 окт. 2025 г.
- CVE-2021-3063722Наблюдать
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
СредняяCVSS 5,4Proof of conceptEPSS 2 %htmly · htmly13 апр. 2021 г.
- CVE-2022-2502221Наблюдать
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in th
СредняяCVSS 5,4Proof of conceptEPSS 1 %htmly · htmly28 февр. 2022 г.
- CVE-2022-108721Наблюдать
htmly Edit Profile Module cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %htmly · htmly29 мар. 2022 г.
- CVE-2021-4286719Наблюдать
A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pa
СредняяCVSS 4,8Эксплойта нетEPSS 1 %htmly · htmly31 мар. 2022 г.
- CVE-2021-4294619Наблюдать
A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %htmly · htmly31 мар. 2022 г.
- CVE-2025-107587Наблюдать
htmly Custom Field post cross site scripting
НизкаяCVSS 1,9Эксплойта нетEPSS 0 %htmly · htmly20 сент. 2025 г.