VendorsW3css_validatorany version
Vulnerabilities

W3 CSS Validator any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-1781
There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This could be exploited to read arbitrary local files if an attacker has access to exception messages.
Published 2025-03-28 · Analyzed
8.4EPSS 0.004