Перейти к содержимому
Noroxi

Записи htmly

16 опубликованных записей вендора htmly.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 19
  2. 21
  3. 22
  4. 24
  5. 25

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

16 записей
  • CVE-2021-36701
    36Наблюдать

    In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    htmly · htmly3 авг. 2021 г.

  • CVE-2021-33354
    32Наблюдать

    Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parame

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    htmly · htmly30 сент. 2022 г.

  • CVE-2021-40285
    32Наблюдать

    htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    htmly · htmly26 авг. 2022 г.

  • CVE-2020-23766
    26Наблюдать

    An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    htmly · htmly21 мая 2021 г.

  • CVE-2024-34191
    26Наблюдать

    htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    htmly · htmly14 мая 2024 г.

  • CVE-2019-8349
    25Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    htmly · htmly8 мая 2019 г.

  • CVE-2021-36702
    24Наблюдать

    The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    htmly · htmly3 авг. 2021 г.

  • CVE-2021-36703
    24Наблюдать

    The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabi

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    htmly · htmly3 авг. 2021 г.

  • CVE-2024-30953
    24Наблюдать

    A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pa

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    htmly · htmly17 апр. 2024 г.

  • CVE-2025-56154
    24Наблюдать

    htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    htmly · htmly2 окт. 2025 г.

  • CVE-2021-30637
    22Наблюдать

    htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.

    СредняяCVSS 5,4Proof of conceptEPSS 2 %

    htmly · htmly13 апр. 2021 г.

  • CVE-2022-25022
    21Наблюдать

    A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in th

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    htmly · htmly28 февр. 2022 г.

  • CVE-2022-1087
    21Наблюдать

    htmly Edit Profile Module cross site scripting

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    htmly · htmly29 мар. 2022 г.

  • CVE-2021-42867
    19Наблюдать

    A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pa

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    htmly · htmly31 мар. 2022 г.

  • CVE-2021-42946
    19Наблюдать

    A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    htmly · htmly31 мар. 2022 г.

  • CVE-2025-10758
    7Наблюдать

    htmly Custom Field post cross site scripting

    НизкаяCVSS 1,9Эксплойта нетEPSS 0 %

    htmly · htmly20 сент. 2025 г.