CVE Browser
CVE-2026-49825 HIGH
lxml: javascript: URL bypass in Cleaner via xlink:href
CVSS 8.2 EPSS 0.30% Aug 20, 2026
CVE-2026-41066 HIGH
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVSS 7.5 EPSS 0.32% Apr 24, 2026
CVE-2024-37388 HIGH
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cau…
CVSS 8.8 EPSS 0.54% Jun 7, 2024
CVE-2022-2309 MEDIUM
NULL Pointer Dereference in lxml/lxml
CVSS 6.9 EPSS 2.43% Jul 5, 2022
CVE-2021-43818 MEDIUM
HTML Cleaner allows crafted and SVG embedded scripts to pass through
CVSS 6.3 EPSS 2.48% Dec 13, 2021
CVE-2021-28957 MEDIUM
python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS
CVSS 5.3 EPSS 4.04% Mar 21, 2021
CVE-2020-27783 MEDIUM
python-lxml: mXSS due to the use of improper parser
CVSS 5.3 EPSS 3.98% Dec 3, 2020
CVE-2018-19787 MEDIUM
python-lxml: XSS in lxml.html.clean module in lxml/html/clean.py
CVSS 5.3 EPSS 2.44% Dec 2, 2018
CVE-2014-3146 MEDIUM
python-lxml: clean_html input sanitization flaw
CVSS 5.3 EPSS 6.33% May 14, 2014
Showing 1 to 9 CVEs · page 1