hexojs/hexo
Releases162
Frequency1 month 9 hours
Last Release
Stars41.8K
A fast, simple & powerful blog framework, powered by Node.js.
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| = 7.0.0, <= 6.3.0, < 7.2.0 | 7.5 HIGH | — | ||
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability. | ||||
| >= 0.0.1, <= 5.4.0, >= 0.0.1, < 6.0.0 | 5 MEDIUM | 1.9 LOW | ||
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code. | ||||