Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0787 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability. |
Github GHSA |
GHSA-xc6g-ggrc-qq4r | Cross-Site Scripting in sanitize-html |
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T01:46:48.797Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16016
No data.
Status : Modified
Published: 2018-06-04T19:29:01.023
Modified: 2026-06-17T01:08:38.803
Link: CVE-2017-16016
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA