CVE-2025-56154
02.10.2025, 16:15
htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.
Awaiting analysis
This vulnerability is currently awaiting analysis.