VendorsOWASPjava_html_sanitizerall versions
Vulnerabilities

OWASP Java HTML Sanitizer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-42575
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Published 2021-10-18 · Modified
9.8EPSS 0.030
CVE-2025-66021
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
Published 2025-11-26 · Analyzed
8.6EPSS 0.002