VDB
Sign up

package

Packagist/symfony/html-sanitizer

pkg:packagist/symfony/html-sanitizer

LOWPackagist
GHSA-hhg7-c65m-h7ff· CVE-2026-45753

Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS)

Modified: 9/10/2026

MEDIUMPackagist
GHSA-qc95-4862-92fh· CVE-2026-45066

Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification

Modified: 9/10/2026

MEDIUMPackagist
GHSA-v3wm-qf9p-c549· CVE-2026-48760

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Modified: 9/10/2026