Microco's vulnerability footprint centers on the BlueMonday HTML sanitization library, a focused security-oriented component used to mitigate cross-site scripting in web applications. The observed weaknesses reflect the inherent complexity of robust HTML parsing and filtering, with documented issues in input neutralization during markup generation. Live severity, exploitation status, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microco over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42576CRITICAL The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION eleme | Oct 18, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-29272MEDIUM bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string. | Mar 27, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microco.
Media articles that mention a CVE ID that affects a product developed by Microco — matched by CVE ID, not by vendor name.