CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

hexo

hexo

2 known vulnerabilities · sorted by CVSS score

CVE-2023-39584
HIGH7.5

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

hexo / hexo+2
Network
Published Sep 8, 2023
CVE-2021-25987
MEDIUM5.0

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

hexo / hexo
Local
Published Nov 30, 2021