Skip to main content

Vendor/product archive

antisamy_project / antisamy CVEs

Beta · best-effort

8 CVEs tagged to antisamy_project / antisamy0 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-23635

Published Feb 2, 2024

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerabili…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43643

Published Oct 9, 2023

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vul…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28367

Published Apr 21, 2022

OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Shee…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14735

Published Sep 25, 2017

OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10006

Published Dec 24, 2016

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply execut…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1