Server-Side Request Forgery Vulnerability in HTMLy by Danpros
CVE-2026-57940

2.1LOW

Key Information:

Vendor

Danpros

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-57940?

HTMLy version 3.1.1 contains a vulnerability allowing authenticated users with administrative privileges to exploit the RSS feed import feature. This occurs in the get_feed() function, which unsafely incorporates user-supplied URLs directly into the file_get_contents() function, lacking proper validation. An attacker can manipulate this by entering specific URLs, potentially leading to unauthorized access to sensitive data or services on the server.

Affected Version(s)

HTMLy PHP 3.1.1

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.