Sanitize-Html
Apostrophecms · 10 CVEs
sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, po…
Jun 12, 2026
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
Jun 12, 2026
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
Apr 15, 2026
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't…
Sep 8, 2025
sanitize-html: sanitize-html cross site scripting
Sep 8, 2025
sanitize-html: Information Exposure when used on the backend
Feb 24, 2024
Regular Expression Denial of Service (ReDoS)
Aug 30, 2022
sanitize-html: improper validation of hostnames set by the "allowedIframeHostnames" option can lead to bypass hostname…
Feb 8, 2021
sanitize-html: improper handling of internationalized domain name (IDN) can lead to bypass hostname whitelist validation
Feb 8, 2021
sanitize-html before 1.4.3 has XSS.
Jan 23, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-53606 | sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, poster, and background attributes | MEDIUM | 0.23% | Jun 12, 2026 |
| CVE-2026-44990 | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` | CRITICAL | 0.69% | Jun 12, 2026 |
| CVE-2026-40186 | ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements | MEDIUM | 0.28% | Apr 15, 2026 |
| CVE-2014-125128 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`h… | MEDIUM | 0.27% | Sep 8, 2025 |
| CVE-2019-25225 | sanitize-html: sanitize-html cross site scripting | MEDIUM | 0.27% | Sep 8, 2025 |
| CVE-2024-21501 | sanitize-html: Information Exposure when used on the backend | MEDIUM | 1.03% | Feb 24, 2024 |
| CVE-2022-25887 | Regular Expression Denial of Service (ReDoS) | HIGH | 1.45% | Aug 30, 2022 |
| CVE-2021-26540 | sanitize-html: improper validation of hostnames set by the "allowedIframeHostnames" option can lead to bypass hostname whitelist for iframe element | MEDIUM | 1.75% | Feb 8, 2021 |
| CVE-2021-26539 | sanitize-html: improper handling of internationalized domain name (IDN) can lead to bypass hostname whitelist validation | MEDIUM | 1.95% | Feb 8, 2021 |
| CVE-2016-1000237 | sanitize-html before 1.4.3 has XSS. | MEDIUM | 0.84% | Jan 23, 2020 |
Showing 1 to 10 of 10 CVEs