justhtml 3.11.0 之前的版本存在跨站脚本(XSS)漏洞。该漏洞源于默认消毒剂在 selectedContent 投影中未能正确移除事件处理程序。攻击者可注入带有事件处理程序的 SVG 或 MathML 元素,这些元素在未被消毒剂处理的情况下被克隆并重新插入输出内容中,从而可能导致存储型或反射型跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | < 3.11.0 |
affected |
3.11.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EmilStenstrom | justhtml | 0 ~ 3.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7808 | 9.8 CRITICAL | justhtml before 1.16.0 Multiple Security Issues via Sanitization |
| CVE-2026-8445 | 9.8 CRITICAL | justhtml before 1.12.0 Sanitizer Bypass via Markdown |
| CVE-2026-5388 | 9.8 CRITICAL | justhtml before 1.15.0 Multiple Security Issues |
| CVE-2026-9769 | 7.5 HIGH | justhtml before 1.10.0 Denial of Service via deeply nested HTML |
| CVE-2026-4671 | 7.5 HIGH | justhtml before 1.18.0 Denial of Service via CSS Selector |
| CVE-2026-77088 | 6.1 MEDIUM | justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span |
| CVE-2026-6827 | 6.1 MEDIUM | justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities |
| CVE-2026-8630 | 6.1 MEDIUM | justhtml before 1.12.0 Mutation XSS via Raw Text Elements |
| CVE-2026-5751 | 6.1 MEDIUM | justhtml before 1.14.0 Mutation XSS via custom sanitization policies |
| CVE-2026-5389 | 6.1 MEDIUM | justhtml before 1.13.0 XSS via code fence breakout |
No comments yet