CVE-2024-25865: Anzhiyu-C Hexo-Theme-Anzhiyu

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.

Affected products

  • Anzhiyu-C Hexo-Theme-Anzhiyu: version 1.6.12 only

Published 2024-03-02. Last modified 2026-06-17.