Apostrophecms
Apostrophecms Sanitize-html: vulnerabilidades y CVE
Apostrophecms Sanitize-html tiene 8 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40186 | Media (6.1) | 0.28% | — | 15 abr 2026 | ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags… |
| CVE-2014-125128 | Media (6.1) | 0.27% | — | 8 sept 2025 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses… |
| CVE-2019-25225 | Media (6.1) | 0.27% | — | 8 sept 2025 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is… |
| CVE-2024-21501 | Media (5.3) | 1.0% | — | 24 feb 2024 | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project… |
| CVE-2022-25887 | Alta (7.5) | 1.5% | — | 30 ago 2022 | The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal. |
| CVE-2021-26540 | Media (5.3) | 1.8% | — | 8 feb 2021 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass… |
| CVE-2021-26539 | Media (5.3) | 2.0% | — | 8 feb 2021 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames"… |
| CVE-2016-1000237 | Media (6.1) | 0.84% | — | 23 ene 2020 | sanitize-html before 1.4.3 has XSS. |