CVE-2025-66021
Published Nov 26, 2025OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS.…
Vendor/product archive
2 CVEs tagged to owasp / java_html_sanitizer — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS.…
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.