VYPR

by Antisamy Project

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-14735Med0.406.10.01Sep 25, 2017OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.
CVE-2016-10006Med0.406.10.01Dec 24, 2016In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.