Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-38949

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Apr 28, 2026
Vendor unknown

Description

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code

References