PT-2025-40403 · Htmly · Htmly

Akinerkisa

·

Published

2025-10-02

·

Updated

2026-01-20

·

CVE-2025-56154

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions htmly version 3.0.8
Description The application is susceptible to Cross Site Scripting (XSS) due to insufficient sanitization of user-supplied input. Specifically, the /author/:name API endpoint does not properly sanitize the name parameter before reflecting it in the HTML response. This allows attackers to inject arbitrary JavaScript payloads.
Recommendations Apply proper input sanitization to the name parameter in the /author/:name endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-56154

Affected Products

Htmly