İçeriğe atla
Noroxi

htmly kayıtları

htmly üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

  1. 19
  2. 21
  3. 22
  4. 24
  5. 25

Çubuk: toplam · koyu kısım: CISA KEV.

Tüm kayıtlar

16 kayıt
  • CVE-2021-36701
    36İzleyin

    In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files.

    KritikCVSS 9,1İstismar yokEPSS %2

    htmly · htmly3 Ağu 2021

  • CVE-2021-33354
    32İzleyin

    Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parame

    YüksekCVSS 8,1İstismar yokEPSS %2

    htmly · htmly30 Eyl 2022

  • CVE-2021-40285
    32İzleyin

    htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

    YüksekCVSS 8,1İstismar yokEPSS %1

    htmly · htmly26 Ağu 2022

  • CVE-2020-23766
    26İzleyin

    An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any

    OrtaCVSS 6,5İstismar yokEPSS %1

    htmly · htmly21 May 2021

  • CVE-2024-34191
    26İzleyin

    htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php.

    OrtaCVSS 6,5İstismar yokEPSS %1

    htmly · htmly14 May 2024

  • CVE-2019-8349
    25İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1)

    OrtaCVSS 6,1İstismar yokEPSS %2

    htmly · htmly8 May 2019

  • CVE-2021-36702
    24İzleyin

    The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    htmly · htmly3 Ağu 2021

  • CVE-2021-36703
    24İzleyin

    The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerabi

    OrtaCVSS 6,1İstismar yokEPSS %1

    htmly · htmly3 Ağu 2021

  • CVE-2024-30953
    24İzleyin

    A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted pa

    OrtaCVSS 6,1İstismar yokEPSS %0

    htmly · htmly17 Nis 2024

  • CVE-2025-56154
    24İzleyin

    htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application.

    OrtaCVSS 6,1İstismar yokEPSS %0

    htmly · htmly2 Eki 2025

  • CVE-2021-30637
    22İzleyin

    htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.

    OrtaCVSS 5,4Kavram kanıtıEPSS %2

    htmly · htmly13 Nis 2021

  • CVE-2022-25022
    21İzleyin

    A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in th

    OrtaCVSS 5,4Kavram kanıtıEPSS %1

    htmly · htmly28 Şub 2022

  • CVE-2022-1087
    21İzleyin

    htmly Edit Profile Module cross site scripting

    OrtaCVSS 5,4İstismar yokEPSS %1

    htmly · htmly29 Mar 2022

  • CVE-2021-42867
    19İzleyin

    A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pa

    OrtaCVSS 4,8İstismar yokEPSS %1

    htmly · htmly31 Mar 2022

  • CVE-2021-42946
    19İzleyin

    A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

    OrtaCVSS 4,8İstismar yokEPSS %1

    htmly · htmly31 Mar 2022

  • htmly Custom Field post cross site scripting

    DüşükCVSS 1,9İstismar yokEPSS %0

    htmly · htmly20 Eyl 2025