Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 21 Jan 2026 03:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 08 Oct 2025 03:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:htmly:htmly:3.0.8:*:*:*:*:*:*:* |
Fri, 03 Oct 2025 17:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Htmly
Htmly htmly |
|
| Vendors & Products |
Htmly
Htmly htmly |
Fri, 03 Oct 2025 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-20T17:34:14.577Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56154
Updated: 2025-10-02T18:14:43.386Z
Status : Modified
Published: 2025-10-02T16:15:34.773
Modified: 2026-01-20T18:16:04.927
Link: CVE-2025-56154
No data.
OpenCVE Enrichment
Updated: 2025-10-03T17:22:30Z