CVE-2019-8349: Htmly

Medium severity, CVSS 6.1. EPSS: 2.2% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.

Affected products

  • Htmly Htmly: version 2.7.4 only

Published 2019-05-08. Last modified 2026-06-17.