Known Vulnerabilities for Tidy by Htacg
Listed below are 5 of the newest known vulnerabilities associated with "Tidy" by "Htacg".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-58240 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev ... | Not Provided | 2025-09-22 | 2026-04-01 |
| CVE-2025-47680 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev ... | Not Provided | 2025-05-23 | 2026-04-01 |
| CVE-2025-23650 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in razvypp Tidy.ro tidyro ... | Not Provided | 2025-02-14 | 2026-04-01 |
| CVE-2024-47736 json | In the Linux kernel, the following vulnerability has been resolved: erofs: handle overlapped pclusters out of crafted images... | Not Provided | 2024-10-21 | 2026-04-11 |
| CVE-2021-33391 json | An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function i... | 9.8 - CRITICAL | 2023-02-17 | 2023-02-28 |
| CVE-2017-17497 json | In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fau... | 7.5 - HIGH | 2017-12-10 | 2020-02-04 |
| CVE-2017-13692 json | In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as... | 7.5 - HIGH | 2017-08-25 | 2017-08-30 |
| CVE-2015-5523 json | The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vec... | 4.3 - MEDIUM | 2015-08-11 | 2016-12-08 |
| CVE-2015-5522 json | Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a den... | 6.8 - MEDIUM | 2015-08-11 | 2016-12-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Htacg | Tidy | 5.7.28 | |||
| Application | Htacg | Tidy | 5.7.0 | |||
| Application | Htacg | Tidy | 5.6.0 | |||
| Application | Htacg | Tidy | 5.5.31 | |||
| Application | Htacg | Tidy | 5.4.0 | |||
| Application | Htacg | Tidy | 5.2.0 | |||
| Application | Htacg | Tidy | 5.1.8 | |||
| Application | Htacg | Tidy | 5.1.25 | |||
| Application | Htacg | Tidy | 5.1.24 | |||
| Application | Htacg | Tidy | 5.1.14 | |||
| Application | Htacg | Tidy | 5.0.0 | |||
| Application | Htacg | Tidy | 4.9.30 |