Hexo is a static site generator for Node.js that produces deployable web content; its narrow vulnerability footprint reflects exposure in file-handling and template-rendering workflows. The documented weakness classes center on path traversal during file operations and cross-site scripting in generated pages, reflecting risks inherent to processing user-supplied input in build and output contexts. Current exploitation status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hexo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39584HIGH Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability. | Sep 8, 2023 | 7.5 | 37 | NO | NO |
CVE-2021-25987MEDIUM Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attack | Nov 30, 2021 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hexo.
Media articles that mention a CVE ID that affects a product developed by Hexo — matched by CVE ID, not by vendor name.