Punkave maintains the sanitize-html library, a focused input-sanitization component widely embedded in web applications to mitigate cross-site scripting risks. The observed vulnerability pattern centers on improper neutralization of untrusted input during HTML rendering, reflecting the inherent complexity of parsing and filtering user-supplied content while preserving intended functionality.
The number and severity of CVEs published that impact products developed by Punkave over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16017MEDIUM sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability. | Jun 4, 2018 | 6.1 | 20 | NO | NO |
CVE-2017-16016MEDIUM Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at | Jun 4, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Punkave.
Media articles that mention a CVE ID that affects a product developed by Punkave — matched by CVE ID, not by vendor name.