VYPR

Bleach

by Mozilla Corporation

Source repositories

CVEs (2)

  • CVE-2020-6816Mar 24, 2020
    risk 0.00cvss epss 0.01

    In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.

  • CVE-2020-6802Mar 24, 2020
    risk 0.00cvss epss 0.02

    In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.