Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
91%
Total Score
98
81
91
100
0
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63670 New sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.17.5. | 0.0.0 - 2.17.5 | Medium |
CVE-2026-84371 New sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.9.0 - 2.17.6. | 1.9.0 - 2.17.6 | Medium |
CVE-2026-53606 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.18.0 - 2.17.4. | 1.18.0 - 2.17.4 | Medium |
CVE-2026-44990 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.17.3 - 2.17.3. | 2.17.3 - 2.17.3 | Critical |
CVE-2026-40186 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.17.2 - 2.17.3. | 2.17.2 - 2.17.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
launder Version ^1.7.1 | — | — |
postcss Version ^8.3.11 | — | — |
deepmerge Version ^4.2.2 | — | — |
htmlparser2 Version ^12.0.0 | — | — |
parse-srcset Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.