Htmly is a lightweight, file-based blogging platform with a focused vulnerability footprint that recurs around its core product and centers on web-application input handling. The vulnerability profile is characterized by recurring weakness classes including cross-site scripting, path traversal, and code injection—typical of template engines and file-processing logic where user input reaches code generation or filesystem operations—with a meaningful share acquiring public exploit availability. Defenders treating Htmly instances should prioritize input sanitization and access controls; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htmly over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45233HIGH HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequ | Jun 25, 2026 | 8.1 | 34 | NO | NO |
CVE-2021-30637MEDIUM htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. | Apr 13, 2021 | 5.4 | 28 | NO | YES |
CVE-2021-33354HIGH Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter. | Sep 30, 2022 | 8.1 | 26 | NO | NO |
CVE-2021-40285HIGH htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php. | Aug 26, 2022 | 8.1 | 26 | NO | NO |
CVE-2021-36701CRITICAL In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files. The vulnerability may allow a remote attacker to delete arbitrary kn | Aug 3, 2021 | 9.1 | 26 | NO | NO |
CVE-2022-25022MEDIUM A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post. | Mar 1, 2022 | 5.4 | 23 | NO | NO |
CVE-2025-56154MEDIUM htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflec | Oct 2, 2025 | 6.1 | 22 | NO | NO |
CVE-2022-1087MEDIUM A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profile Module. The manipulation of the field Title with script ta | Mar 29, 2022 | 5.4 | 21 | NO | NO |
CVE-2021-36702MEDIUM The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote a | Aug 3, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-23766MEDIUM An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Adm | May 21, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htmly.
Media articles that mention a CVE ID that affects a product developed by Htmly — matched by CVE ID, not by vendor name.