Lucene search

K

Hugo Security Vulnerabilities

cve
cve

CVE-2020-26284

Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's os/exec for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system %PATH% on Windows. In Hugo before version 0.79.1, if a malicious file with the same name (exe or bat) is...

8.5CVSS

8.4AI Score

0.002EPSS

2020-12-21 11:15 PM
54
2
cve
cve

CVE-2024-32875

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who have these hooks enabled and do not trust their Markdown content files. The iss...

6.1CVSS

6.2AI Score

0.0004EPSS

2024-04-23 09:15 PM
45