Vulnerabilities (CVE)

Filtered by vendor Apostrophecms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25887 1 Apostrophecms 1 Sanitize-html 2023-08-08 N/A 7.5 HIGH
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.