CVE-2019-8349: Htmly
Medium severity, CVSS 6.1. EPSS: 2.2% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.
Affected products
- Htmly Htmly: version 2.7.4 only
Published 2019-05-08. Last modified 2026-06-17.