The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-17606.json"