Cross Site Scripting Vulnerability in htmly by Danpros
CVE-2025-56154
6.1MEDIUM
What is CVE-2025-56154?
The htmly version 3.0.8 contains a Cross Site Scripting (XSS) vulnerability that affects the /author/:name endpoint. The application fails to adequately sanitize the 'name' parameter before rendering it in the HTML output. This oversight allows attackers to exploit the vulnerability by injecting arbitrary JavaScript code, which can be executed in the context of the user's browser. Successful exploitation could lead to data theft, session hijacking, and other potentially harmful actions within the affected web application.
