Description
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.3.0
References
Could your website be exposed too?
SmartScanner can check your website for hexo-admin plugin for Node.js XSS Vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407
- Cross-Site Scripting in hexo-admin - Vulnerability
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761
- @vendure/admin-ui-plugin authenticated Cross-site Scripting vulnerability - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated September 26, 2023


