Every CVE whose affected-product data names Gohugo Hugo, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (16)
CVE-2026-75926 — CVSS 8.6 (high): Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or…
CVE-2026-100693 — CVSS 8.4 (high): Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that…
CVE-2026-44301 — CVSS 8.1 (high): Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS…
CVE-2020-26284 — CVSS 7.7 (high): Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of…
CVE-2026-100692 — CVSS 7.5 (high): Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount…
CVE-2026-100690 — CVSS 7.5 (high): Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model…
CVE-2026-58404 — CVSS 6.8 (medium): Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback…
CVE-2026-58403 — CVSS 6.5 (medium): Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot…
CVE-2026-100694 — CVSS 6.1 (medium): Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered…
CVE-2026-50133 — CVSS 6.1 (medium): Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html…
CVE-2026-50134 — CVSS 5.8 (medium): Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with…
CVE-2026-50135 — CVSS 5.5 (medium): Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of…
CVE-2026-58402 — CVSS 5.4 (medium): Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or…
CVE-2026-10618 — CVSS 5.4 (medium): Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without…
CVE-2026-100691 — CVSS 5.4 (medium): Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the…
CVE-2026-35166 — CVSS 5.4 (medium): Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not…