Known Vulnerabilities for Sanitize-html by Apostrophecms
Listed below are 5 of the newest known vulnerabilities associated with "Sanitize-html" by "Apostrophecms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103292 json | Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted b... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-102372 json | GestSup versions before 3.2.61 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthentica... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-89243 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in U... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-86751 json | Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read a... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86741 json | Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation ema... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-85601 json | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} d... | Not Provided | 2026-09-04 | 2026-09-10 |
| CVE-2026-85386 json | Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. ... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-84701 json | NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malic... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84371 json | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a ... | Not Provided | 2026-09-01 | 2026-09-02 |
| CVE-2026-83532 json | The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before... | Not Provided | 2026-09-12 | 2026-09-12 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apostrophecms | Sanitize-html | 2.3.2 | |||
| Application | Apostrophecms | Sanitize-html | 2.3.1 | |||
| Application | Apostrophecms | Sanitize-html | 2.3.0 | |||
| Application | Apostrophecms | Sanitize-html | 2.2.0 | |||
| Application | Apostrophecms | Sanitize-html | 2.1.2 | |||
| Application | Apostrophecms | Sanitize-html | 2.1.1 | |||
| Application | Apostrophecms | Sanitize-html | 2.1.0 | |||
| Application | Apostrophecms | Sanitize-html | 2.0.0 | |||
| Application | Apostrophecms | Sanitize-html | 1.9.0 | |||
| Application | Apostrophecms | Sanitize-html | 1.8.0 | |||
| Application | Apostrophecms | Sanitize-html | 1.7.2 | |||
| Application | Apostrophecms | Sanitize-html | 1.7.1 | |||
| Application | Apostrophecms | Sanitize-html | 1.7.0 | |||
| Application | Apostrophecms | Sanitize-html | 1.6.1 | |||
| Application | Apostrophecms | Sanitize-html | 1.6.0 | |||
| Application | Apostrophecms | Sanitize-html | 1.5.3 | |||
| Application | Apostrophecms | Sanitize-html | 1.5.2 | |||
| Application | Apostrophecms | Sanitize-html | 1.5.1 | |||
| Application | Apostrophecms | Sanitize-html | 1.5.0 | |||
| Application | Apostrophecms | Sanitize-html | 1.4.3 |