« Volver al listado

Apostrophecms

Apostrophecms Sanitize-html: vulnerabilidades y CVE

Apostrophecms Sanitize-html tiene 8 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses1
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-40186Media (6.1)0.28%—15 abr 2026
ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags…
CVE-2014-125128Media (6.1)0.27%—8 sept 2025
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses…
CVE-2019-25225Media (6.1)0.27%—8 sept 2025
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is…
CVE-2024-21501Media (5.3)1.0%—24 feb 2024
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project…
CVE-2022-25887Alta (7.5)1.5%—30 ago 2022
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
CVE-2021-26540Media (5.3)1.8%—8 feb 2021
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass…
CVE-2021-26539Media (5.3)2.0%—8 feb 2021
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames"…
CVE-2016-1000237Media (6.1)0.84%—23 ene 2020
sanitize-html before 1.4.3 has XSS.

Otros productos de Apostrophecms