Cross Site Scripting Vulnerability in htmly by Danpros
CVE-2025-56154

6.1MEDIUM

Key Information:

Vendor

Danpros

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-56154?

The htmly version 3.0.8 contains a Cross Site Scripting (XSS) vulnerability that affects the /author/:name endpoint. The application fails to adequately sanitize the 'name' parameter before rendering it in the HTML output. This oversight allows attackers to exploit the vulnerability by injecting arbitrary JavaScript code, which can be executed in the context of the user's browser. Successful exploitation could lead to data theft, session hijacking, and other potentially harmful actions within the affected web application.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.