CVE-2026-38949

HTMLy 3.1.1 - XSS

Title source: llm
STIX 2.1

Description

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code

Scores

EPSS 0.0002
EPSS Percentile 4.1%

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Published Apr 28, 2026
Tracked Since Apr 29, 2026