CVE-2026-38949: XSS
Published Apr 28, 2026
·Updated
Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code
Affected Software
1 affected component
Htmly Htmly=3.1.1
Event History
Apr 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-38949?
CVE-2026-38949 has a severity rating of high, with a CVSS score of 8.9.
2
How do I fix CVE-2026-38949?
To mitigate CVE-2026-38949, update HTMLy to a version that addresses the XSS vulnerability in the content creation functionality.
3
What type of vulnerability is CVE-2026-38949?
CVE-2026-38949 is classified as a Cross-Site Scripting (XSS) vulnerability.
4
Where is the vulnerability located in CVE-2026-38949?
CVE-2026-38949 is located in the content creation functionality at the /add/content?type=image endpoint.
5
What is the impact of CVE-2026-38949?
The impact of CVE-2026-38949 includes the potential injection of arbitrary code due to improper sanitization of user input.