Vulnerabilities (CVE)

Filtered by vendor Svg-sanitizer Project Subscribe
Filtered by product Svg-sanitizer
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18857 1 Svg-sanitizer Project 1 Svg-sanitizer 2020-08-24 5.0 MEDIUM 7.5 HIGH
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.