The OWASP Java HTML Sanitizer Project maintains a focused library designed to strip potentially malicious HTML and JavaScript from user-supplied content in Java applications, serving as a defense layer in web applications handling untrusted markup. With a single product in the landscape, vulnerabilities affecting this sanitizer concentrate on the parsing and filtering logic that underpins its core function. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Owasp Java Html Sanitizer Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a | Nov 17, 2011 | 2.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Owasp Java Html Sanitizer Project.
Media articles that mention a CVE ID that affects a product developed by Owasp Java Html Sanitizer Project — matched by CVE ID, not by vendor name.