VYPR

Java HTML Sanitizer

by Trustwave

Source repositories

CVEs (2)

  • CVE-2021-42575CriOct 18, 2021
    risk 0.64cvss 9.8epss 0.03

    The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

  • CVE-2025-66021MedNov 26, 2025
    risk 0.33cvss 6.1epss 0.00

    OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1, OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows…