Antisamy
Antisamy Project · 8 CVEs
AntiSamy malicious input can provoke XSS when preserving comments
Feb 2, 2024
mXSS in AntiSamy
Oct 9, 2023
OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serialize…
Apr 21, 2022
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serialize…
Apr 21, 2022
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes e…
Apr 21, 2022
AntiSamy: XSS via HTML attributes
Jul 19, 2021
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript:…
Sep 25, 2017
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content)…
Dec 24, 2016
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-23635 | AntiSamy malicious input can provoke XSS when preserving comments | MEDIUM | 0.37% | Feb 2, 2024 |
| CVE-2023-43643 | mXSS in AntiSamy | MEDIUM | 0.47% | Oct 9, 2023 |
| CVE-2022-29577 | OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed… | MEDIUM | 1.33% | Apr 21, 2022 |
| CVE-2022-28367 | OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed… | MEDIUM | 1.01% | Apr 21, 2022 |
| CVE-2022-28366 | Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In par… | HIGH | 2.13% | Apr 21, 2022 |
| CVE-2021-35043 | AntiSamy: XSS via HTML attributes | HIGH | 1.51% | Jul 19, 2021 |
| CVE-2017-14735 | OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL. | MEDIUM | 1.66% | Sep 25, 2017 |
| CVE-2016-10006 | In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protectio… | MEDIUM | 2.35% | Dec 24, 2016 |
Showing 1 to 8 of 8 CVEs