Known vulnerabilities in sanitize-html
Vendor:
ApostropheCMS
Software:
sanitize-html
Software CPE:
cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:*:*:*
Website:
https://apostrophecms.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.17.0
2.16.0
2.15.0
2.14.0
2.13.1
2.13.0
2.12.1
2.11.0
2.10.0
2.9.0
2.8.1
2.8.0
2.7.3
2.7.2
2.7.1
2.7.0
2.6.1
2.6.0
2.5.3
2.5.2
2.5.1
2.5.0
2.4.0
2.3.3
2.3.2
2.3.1
2.3.0
2.2.0
2.1.2
2.1.1
2.1.0
2.0.0
1.27.4
1.22.0
1.21.1
1.21.0
1.20.0
1.19.3
1.19.2
1.19.1
1.19.0
1.18.5
1.18.4
1.18.3
1.18.2
1.11.4
1.11.1
1.11.0
1.10.1
1.9.0
1.8.0
1.7.2
1.7.1
1.7.0
1.5.2
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU88801 - Exposure of sensitive information to an unauthorized actor CVE-2024-21501 |
CWE-200 | Medium | 2.12.1 | 17.04.2024 |
SB20240417144 SB20240417145 SB2024050632 and 7 more |
||
| #VU68954 - Incorrect Regular Expression CVE-2022-25887 |
CWE-185 | Medium | 2.7.1 | 02.11.2022 |
SB2022110267 SB2022110270 SB2023013024 and 2 more |
||
| #VU46693 - Improper Control of Generation of Code ('Code Injection') |
CWE-94 | High | 2.0.0 | 14.09.2020 |
SB2020091423 |