« Back to list

Owasp

Owasp Java Html Sanitizer: vulnerabilities and CVEs

Owasp Java Html Sanitizer has 2 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months1
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-66021High (8.6)0.25%—Nov 26, 2025
OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1, OWASP java html…
CVE-2021-42575Critical (9.8)3.0%—Oct 18, 2021
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Other products by Owasp