Provides an object-oriented API to sanitize untrusted HTML input for safe insertion into a document's DOM.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-48760 symfony/html-sanitizer is vulnerable to User Interface (UI) Misrepresentation of Critical Information in versions 6.1.0 - 6.4.41, 7.0.0 - 7.4.13 and 8.0.0 - 8.0.13. | 6.1.0 - 6.4.417.0.0 - 7.4.138.0.0 - 8.0.13 | Low |
CVE-2026-48761 symfony/html-sanitizer is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.1.0 - 6.4.41, 7.0.0 - 7.4.13 and 8.0.0 - 8.0.13. | 6.1.0 - 6.4.417.0.0 - 7.4.138.0.0 - 8.0.13 | Medium |
AIKIDO-2026-10871 symfony/html-sanitizer is vulnerable to Interpretation Conflict in versions 6.1.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 6.1.0 - 6.4.397.0.0 - 7.4.118.0.0 - 8.0.11 | Medium |
AIKIDO-2026-10870 symfony/html-sanitizer is vulnerable to Cross-site Scripting (XSS) in versions 6.1.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 6.1.0 - 6.4.397.0.0 - 7.4.118.0.0 - 8.0.11 | Low |
AIKIDO-2026-10872 symfony/html-sanitizer is vulnerable to User Interface (UI) Misrepresentation of Critical Information in versions 6.1.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 6.1.0 - 6.4.397.0.0 - 7.4.118.0.0 - 8.0.11 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^6.5|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant