Medium severity6.1NVD Advisory· Published Sep 13, 2022· Updated Jun 17, 2026
CVE-2022-36020
CVE-2022-36020
Description
The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package masterminds/html5, malicious markup used in a sequence with special HTML comments cannot be filtered and sanitized. This allows for a bypass of the cross-site scripting mechanism of typo3/html-sanitizer. This issue has been addressed in versions 1.0.7 and 2.0.16 of the typo3/html-sanitizer package. Users are advised to upgrade. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/html-sanitizerPackagist | >= 1.0.0, < 1.0.7 | 1.0.7 |
typo3/html-sanitizerPackagist | >= 2.0.0, < 2.0.16 | 2.0.16 |
typo3/cms-corePackagist | >= 10.0.0, < 10.4.32 | 10.4.32 |
typo3/cms-corePackagist | >= 11.0.0, < 11.5.16 | 11.5.16 |
typo3/cmsPackagist | >= 10.0.0, < 10.4.32 | 10.4.32 |
typo3/cmsPackagist | >= 11.0.0, < 11.5.16 | 11.5.16 |
Affected products
5cpe:2.3:a:typo3:html_sanitizer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:typo3:html_sanitizer:*:*:*:*:*:*:*:*range: >=1.0.0,<1.0.7
- (no CPE)range: >= 1.0.0, < 1.0.7
- ghsa-coords3 versions
>= 10.0.0, < 10.4.32+ 2 more
- (no CPE)range: >= 10.0.0, < 10.4.32
- (no CPE)range: >= 10.0.0, < 10.4.32
- (no CPE)range: >= 1.0.0, < 1.0.7
Patches
Vulnerability mechanics
References
10- github.com/TYPO3/html-sanitizer/commit/60bfdc7f9b394d0236e16ee4cea8372a7defa493nvdPatchThird Party AdvisoryWEB
- github.com/TYPO3/html-sanitizer/security/advisories/GHSA-47m6-46mj-p235nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-47m6-46mj-p235ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-36020ghsaADVISORY
- packagist.org/packages/masterminds/html5nvdThird Party AdvisoryWEB
- packagist.org/packages/typo3/html-sanitizernvdProductThird Party AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2022-36020.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2022-36020.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/html-sanitizer/CVE-2022-36020.yamlghsaWEB
- typo3.org/security/advisory/typo3-core-sa-2022-011ghsaWEB
News mentions
0No linked articles in our index yet.