The Sanitize Project maintains a focused sanitization library whose modest disclosure footprint belies its broad integration across web frameworks and content-filtering applications. The observed vulnerabilities concentrate on input-handling mechanisms central to the product's function, specifically cross-site scripting and input-validation weaknesses that are characteristic of sanitization and encoding logic. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sanitize Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3740HIGH A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. | Mar 30, 2018 | 7.5 | 24 | NO | NO |
CVE-2023-23627MEDIUM Sanitize is an allowlist-based HTML and CSS sanitizer. Versions 5.0.0 and later, prior to 6.0.1, are vulnerable to Cross-site Scripting. When Sanitize is configured with a custom a | Jan 28, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-36823MEDIUM Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version | Jul 6, 2023 | 6.1 | 19 | NO | NO |
CVE-2020-4054HIGH In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" | Jun 16, 2020 | 7.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sanitize Project.
Media articles that mention a CVE ID that affects a product developed by Sanitize Project — matched by CVE ID, not by vendor name.