The Htmlsanitizer Project maintains a focused, niche HTML-sanitization library deployed across web applications requiring user-generated content filtering. Its vulnerability profile centers on the product's role in output encoding and injection prevention, with the recurrent signal being weaknesses in cross-site scripting mitigation, output escaping, and downstream injection—the core architectural demands of a sanitizer. Current CVE counts, exploitation activity, and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htmlsanitizer Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25543MEDIUM HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template | Feb 4, 2026 | 6.1 | 21 | NO | NO |
CVE-2020-26293MEDIUM HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible | Jan 4, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-44390MEDIUM HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign con | Oct 5, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htmlsanitizer Project.
Media articles that mention a CVE ID that affects a product developed by Htmlsanitizer Project — matched by CVE ID, not by vendor name.