216.73.216.233

CVE-2026-25543

· Published 04/02/2026 22:16 · Modified 05/02/2026 14:57

Labels: CVE-2026-25543 2026-02-04CVE-2026-25543CWE-116[email protected]

Essential information

Published
04/02/2026 22:16
Modified
05/02/2026 14:57
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
htmlsanitizer / htmlsanitizer cpe:2.3:a:htmlsanitizer:htmlsanitizer:<9.0.892:*:*:*:*:*:*:*
htmlsanitizer / htmlsanitizer cpe:2.3:a:htmlsanitizer:htmlsanitizer:<9.1.893-beta:*:*:*:*:*:*:*

References