← Back

Dom Sanitizer

dom-sanitizer

Vendor: Getgrav • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Getgrav
1Dom Sanitizer
Nov 21, 2024
Nov 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.