216.73.216.197

CVE-2026-47344

· Published 08/06/2026 20:17 · Modified 09/06/2026 13:46

Labels: CVE-2026-47344 2026-06-08CVE-2026-47344CWE-79f4fb688c-4412-4426-b4b8-421ecf27b14a

Essential information

Published
08/06/2026 20:17
Modified
09/06/2026 13:46
Author
Creator
CVSS
2.1 LOW (v3) 2.1 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f4fb688c-4412-4426-b4b8-421ecf27b14a
NVD
View on NVD

Affected products (CPE)

ProductCPE
typo3 / html-sanitizer cpe:2.3:a:typo3:html-sanitizer:<2.3.2:*:*:*:*:*:*:*

References