Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
{ "github_reviewed_at": "2021-12-01T16:15:32Z", "nvd_published_at": "2021-11-30T14:15:00Z", "github_reviewed": true, "cwe_ids": [ "CWE-79" ], "severity": "MODERATE" }