Vulnerability Description
Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Chittu13/cve-research/blob/main/CVE-2026-38949/README.md
- https://github.com/danpros/htmly
- https://youtu.be/3e-tzUMCox8
- https://github.com/Chittu13/cve-research/blob/main/CVE-2026-38949/README.md
FAQ
What is CVE-2026-38949?
CVE-2026-38949 is a vulnerability with a CVSS score of 8.9 (HIGH). Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user in...
How severe is CVE-2026-38949?
CVE-2026-38949 has been rated HIGH with a CVSS base score of 8.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-38949?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.