Vendorsrrrenehtmlsanitizeexany version
Vulnerabilities

rrrene HTMLSanitizeEx any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-68749
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
Published 2026-08-06 · Modified
8.2EPSS 0.008
CVE-2026-68750
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Published 2026-08-06 · Modified
8.2EPSS 0.008
CVE-2026-66829
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
Published 2026-08-06 · Modified
6.1EPSS 0.006
CVE-2026-66843
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
Published 2026-08-06 · Modified
6.1EPSS 0.005
CVE-2026-68747
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
Published 2026-08-06 · Modified
6.1EPSS 0.004
CVE-2026-66370
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
Published 2026-08-06 · Modified
6.1EPSS 0.004