Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-39584 | Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability. Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability. NVD description · AI analysis pending | 7.5 | 35% |
| — | ||
| CVE-2022-24656 | HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-25987 | Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2019-17606 | The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post. The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2019-1010005 | HexoEditor v1.1.8-beta is affected by: HexoEditor v1.1.8-beta is affected by: XSS to code execution. NVD description · AI analysis pending | 6.1 | 1% | PoC ×2 |
| — |