Sorry in advance if you were joking, but for readers who aren't in the know: Hugo had, in fact, two 9.3 CVSS vulnerabilities just 11 days ago...
https://app.opencve.io/cve/CVE-2026-89259
https://app.opencve.io/cve/CVE-2026-89258
To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE
To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE