ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-39584
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

NVD description · AI analysis pending
7.535%
  • hexo hexo
CVE-2022-24656
HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS).

HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times.

NVD description · AI analysis pending
6.1<1% PoC
  • hexoeditor project hexoeditor
CVE-2021-25987
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS.

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

NVD description · AI analysis pending
4.6<1%
  • hexo hexo
CVE-2019-17606
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.

The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.

NVD description · AI analysis pending
6.11%
  • hexo-admin project hexo-admin
CVE-2019-1010005
HexoEditor v1.1.8-beta is affected by:

HexoEditor v1.1.8-beta is affected by: XSS to code execution.

NVD description · AI analysis pending
6.11% PoC ×2
  • hexoeditor project hexoeditor