Home/Product/rubyonrails html sanitizer
Product

rubyonrails html sanitizer

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-25543
< 9.0.892
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to v
6.1MEDIUM
CVE-2023-47125
>= 1.0.0 and < 1.5.3
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing in
4.7MEDIUM
CVE-2023-44390
< 8.0.723
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulner
6.1MEDIUM
CVE-2023-38500
>= 1.0.0 and < 1.5.1
TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly
4.7MEDIUM
CVE-2022-23499
>= 1.0.0 and <= 1.0.7
HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In ve
6.1MEDIUM
CVE-2022-36020
>= 1.0.0 and < 1.0.7
The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allow
6.1MEDIUM
CVE-2020-26293
< 5.0.372
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSan
6.1MEDIUM
CVE-2018-3741
<= 1.0.3
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whiteliste
6.1MEDIUM
CVE-2015-7580
<= 1.0.2
Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on R
6.1MEDIUM
CVE-2015-7579
<= 1.0.2
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attac
6.1MEDIUM
CVE-2015-7578
<= 1.0.2
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remot
6.1MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin