CVE-2024-57329: Hortusfox
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
Affected products
- Hortusfox Hortusfox: version 3.9 only
Published 2025-01-23. Last modified 2026-06-17.