product of gohugo

hugo

7 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

github.com/gohugoio/hugo: Hugo: Cross-site scripting via unescaped HTML in Org Mode content
CVE-2026-100694
Severity medium
github.com/gohugoio/hugo: Hugo: Security restriction bypass via mixed-case URL schemes
CVE-2026-100693
Severity high
github.com/gohugoio/hugo: Hugo: Information disclosure via symlinked mount roots
CVE-2026-100692
Severity high
github.com/gohugoio/hugo: Hugo: Stored cross-site scripting via unescaped lineAnchors option
CVE-2026-100691
Severity medium
github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape
CVE-2026-100690
Severity high
github.com/gohugoio/hugo: tailwindcss: Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant
CVE-2026-75926
Severity critical
github.com/gohugoio/hugo: Hugo: Stored Cross-Site Scripting via unescaped code-fence attribute values
CVE-2026-10618
Severity medium