CVE-2024-57329: Hortusfox

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

Affected products

Published 2025-01-23. Last modified 2026-06-17.