Antisamy Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-23635

    AntiSamy malicious input can provoke XSS when preserving comments

    Last Modified: Nov 21, 2024
    Published: Feb 02, 2024

    CVE-2023-43643

    mXSS in AntiSamy

    Last Modified: Nov 21, 2024
    Published: Oct 09, 2023

    CVE-2022-29577

    OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.

    Last Modified: Nov 21, 2024
    Published: Apr 21, 2022

    CVE-2022-28367

    OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.

    Last Modified: Nov 21, 2024
    Published: Apr 21, 2022

    CVE-2022-28366

    Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.

    Last Modified: Nov 21, 2024
    Published: Apr 21, 2022
    Items Per Page
    Antisamy_Project Vulnerabilities & Security CVEs | CVE-DB