13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether sanitize-html is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.4
CVE-2026-84371
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
MEDIUM 5.3
CVE-2024-21501
sanitize-html Information Exposure vulnerability
MEDIUM 6.1
CVE-2026-63670
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
MEDIUM 5.4
CVE-2026-53606
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
CRITICAL 9.3
CVE-2026-44990
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
MEDIUM 6.1
CVE-2026-40186
sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
MEDIUM 6.1
CVE-2019-25225
sanitize-html is vulnerable to XSS through incomprehensive sanitization
HIGH 7.5
CVE-2022-25887
Sanitize-html Vulnerable To REDoS Attacks
MEDIUM 5.3
CVE-2021-26540
Improper Input Validation in sanitize-html
MEDIUM 5.3
CVE-2021-26539
Improper Input Validation in sanitize-html
MEDIUM 6.1
CVE-2017-16017
Cross-Site Scripting in sanitize-html
UNKNOWN
CVE-2017-16016
Cross-Site Scripting in sanitize-html
MEDIUM 6.1
CVE-2016-1000237
Cross-Site Scripting in sanitize-html
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes