HTML Purifier is a widely embedded PHP library for sanitizing HTML input, and its vulnerability profile reflects the complexity of parsing and neutralization logic inherent to content-filtering libraries. Observed weaknesses center on cross-site scripting flaws in the sanitization process itself and occasional information disclosure, capturing the ongoing tension between filtering rigor and parser correctness. Current CVE counts, severity breakdown, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htmlpurifier over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4183MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via | Nov 5, 2010 | 4.3 | 18 | NO | NO |
CVE-2011-3744MEDIUM HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonst | Sep 23, 2011 | 5.0 | 17 | NO | NO |
CVE-2010-2479MEDIUM Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inje | Jul 6, 2010 | 4.3 | 17 | NO | NO |
CVE-2007-3498MEDIUM Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified v | Jun 29, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htmlpurifier.
Media articles that mention a CVE ID that affects a product developed by Htmlpurifier — matched by CVE ID, not by vendor name.