CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “hexo”

8 vulnerabilities found for “hexo”

CVE-2025-5011
LOW2.4

A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

moonlightl / hexo-boot
Network
Published May 21, 2025
CVE-2025-5010
LOW2.4

A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog Backend. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

moonlightl / hexo-boot
Network
Published May 21, 2025
CVE-2024-25865
MEDIUM6.1

Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.

anzhiyu-c / hexo-theme-anzhiyu
Network
Published Mar 2, 2024
CVE-2023-39584
HIGH7.5

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

hexo / hexo+2
Network
Published Sep 8, 2023
CVE-2022-24656
MEDIUM6.1

HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times.

hexoeditor_project / hexoeditor
Network
Published Mar 21, 2022
CVE-2021-25987
MEDIUM5.0

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

hexo / hexo
Local
Published Nov 30, 2021
CVE-2019-17606
MEDIUM6.1

The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.

hexo-admin_project / hexo-admin
Network
Published Oct 23, 2019
CVE-2019-1010005
MEDIUM6.1

HexoEditor v1.1.8-beta is affected by: XSS to code execution.

hexoeditor_project / hexoeditor
Network
Published Jul 15, 2019