Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Htmlpurifier

First CVE: Jun 29, 2007Active for: 19 yearsTotal CVEs: 4

HTML Purifier is a widely embedded PHP library for sanitizing HTML input, and its vulnerability profile reflects the complexity of parsing and neutralization logic inherent to content-filtering libraries. Observed weaknesses center on cross-site scripting flaws in the sanitization process itself and occasional information disclosure, capturing the ongoing tension between filtering rigor and parser correctness. Current CVE counts, severity breakdown, and exploitation status are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
4.5
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Htmlpurifier over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2007
19 years ago
Most Recent CVE
Sep 23, 2011
5,418 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4183MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via
Nov 5, 20104.318NONO
CVE-2011-3744MEDIUM
HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonst
Sep 23, 20115.017NONO
CVE-2010-2479MEDIUM
Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inje
Jul 6, 20104.317NONO
CVE-2007-3498MEDIUM
Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified v
Jun 29, 20074.314NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown4 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown4 (100.0%)
User Interaction
None0 (0.0%)
Unknown4 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Htmlpurifier.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Htmlpurifier — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Htmlpurifier's Products

View all 2 CNAs →

Top CWEs