The Antisamy Project maintains a specialized HTML sanitization library widely embedded in applications requiring content filtering and cross-site scripting mitigation, giving the library outsized importance despite its narrow product scope. Its disclosures center on the library's core function: neutralization of potentially malicious input during web page generation, reflecting the inherent difficulty of maintaining a reliable allowlist-based XSS filter across evolving HTML and JavaScript specifications. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antisamy Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28366HIGH Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue e | Apr 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2016-10006MEDIUM In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executa | Dec 24, 2016 | 6.1 | 23 | NO | NO |
CVE-2022-29577MEDIUM OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheet | Apr 21, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-35043MEDIUM OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as | Jul 19, 2021 | 6.1 | 22 | NO | NO |
CVE-2017-14735MEDIUM OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL. | Sep 25, 2017 | 6.1 | 22 | NO | NO |
CVE-2022-28367MEDIUM OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheet | Apr 21, 2022 | 6.1 | 21 | NO | NO |
CVE-2023-43643MEDIUM AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vuln | Oct 9, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-23635MEDIUM AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerabilit | Feb 2, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antisamy Project.
Media articles that mention a CVE ID that affects a product developed by Antisamy Project — matched by CVE ID, not by vendor name.