← Back to CVE List

CVE-2021-25987

Published: 2021-11-30T14:15Z
Last Modified: 2024-11-21T05:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt