We found results for “”
CVE-2026-25543
Good to know:
Date: February 4, 2026
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
Improper Encoding or Escaping of Output
CWE-116Top Fix
Upgrade Version
Upgrade to version htmlsanitizer - 9.0.892;htmlsanitizer - 9.1.893-beta;https://github.com/mganss/HtmlSanitizer.git - v9.0.892
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


