gohugo
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 21, 2020 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Hugo symlink confinement bypass in os.ReadFile
Hugo default code block renderer XSS via unescaped code-fence language
Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings
Hugo: Symlink confinement bypass in resources.Get
Hugo: security.http.urls allow-list bypass via HTTP redirects
Hugo: XSS via text/html content files
Hugo: Node tool execution allows file system access outside the project directory
Hugo does not properly escape some Markdown links
Hugo can execute a binary from the current directory on Windows
Monitor gohugo in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.