Description
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
Remediation
References
https://github.com/hexojs/hexo/commit/5170df2d3fa9c69e855c4b7c2b084ebfd92d5200
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25987
Related Vulnerabilities
CVE-2022-24717 Vulnerability in npm package @finastra/ssr-pages
CVE-2023-25157 Vulnerability in maven package org.geoserver.community:gs-jdbcconfig
CVE-2022-42466 Vulnerability in maven package org.apache.isis.commons:isis-commons
CVE-2022-1274 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2019-16147 Vulnerability in maven package com.liferay:com.liferay.journal.taglib