NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-38949
Summary

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code

Publication Date April 29, 2026, 4:37 a.m.
Registration Date April 30, 2026, 4:09 a.m.
Last Update April 30, 2026, 1:16 a.m.
Related information, measures and tools
Common Vulnerabilities List