A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link Name parameter of Menu Editor module.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Aug 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Htmly
Htmly htmly
CPEs cpe:2.3:a:htmly:htmly:2.9.5:*:*:*:*:*:*:*
Vendors & Products Htmly
Htmly htmly

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T01:46:03.369Z

Reserved: 2024-03-27T00:00:00

Link: CVE-2024-30953

cve-icon Vulnrichment

Updated: 2024-08-02T01:46:03.369Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-17T19:15:07.470

Modified: 2025-08-21T00:46:26.630

Link: CVE-2024-30953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.