Loading market data...
← Back to CVE feed

CVE-2026-38949

UNKNOWN View on NVD ↗

Description

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code

Published: Apr 28, 2026 19:37 UTC Modified: Apr 29, 2026 16:16 UTC