vendor
gohugo
Severity
Its products
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| github.com/gohugoio/hugo: Hugo: Cross-site scripting via unescaped HTML in Org Mode content CVE-2026-100694 | Severity medium |
| github.com/gohugoio/hugo: Hugo: Security restriction bypass via mixed-case URL schemes CVE-2026-100693 | Severity high |
| github.com/gohugoio/hugo: Hugo: Information disclosure via symlinked mount roots CVE-2026-100692 | Severity high |
| github.com/gohugoio/hugo: Hugo: Stored cross-site scripting via unescaped lineAnchors option CVE-2026-100691 | Severity medium |
| github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape CVE-2026-100690 | Severity high |
| github.com/gohugoio/hugo: tailwindcss: Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant CVE-2026-75926 | Severity critical |
| github.com/gohugoio/hugo: Hugo: Stored Cross-Site Scripting via unescaped code-fence attribute values CVE-2026-10618 | Severity medium |