github.com/microcosm-cc/bluemonday
Activity
- Latest release
- 2y ago
- Total releases
- 20
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Apr 13, 2021
| Version | Released | |
|---|---|---|
v1.0.27
patch
|
v1.0.27
patch
Dependencies (2)
|
|
v1.0.26
patch
|
v1.0.26
patch
Dependencies (2)
|
|
v1.0.25
patch
|
v1.0.25
patch
Dependencies (2)
|
|
v1.0.24
patch
|
v1.0.24
patch
Dependencies (2)
|
|
v1.0.23
patch
|
v1.0.23
patch
Dependencies (2)
|
|
v1.0.22
patch
|
v1.0.22
patch
Dependencies (2)
|
|
v1.0.21
patch
|
v1.0.21
patch
Dependencies (2)
|
|
v1.0.20
patch
|
v1.0.20
patch
Dependencies (2)
|
|
v1.0.19
patch
|
v1.0.19
patch
Dependencies (2)
|
|
v1.0.18
patch
|
v1.0.18
patch
Dependencies (2)
|
|
v1.0.17
patch
|
v1.0.17
patch
Dependencies (2)
|
|
v1.0.16
patch
|
v1.0.16
patch
Dependencies (2)
|
|
v1.0.15
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.15
patch
Dependencies (3)
|
|
v1.0.14
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.14
patch
Dependencies (2)
|
|
v1.0.13
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.13
patch
Dependencies (2)
|
|
v1.0.12
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.12
patch
Dependencies (2)
|
|
v1.0.11
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.11
patch
Dependencies (2)
|
|
v1.0.10
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.10
patch
Dependencies (2)
|
|
v1.0.9
patch
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.9
patch
Dependencies (2)
|
|
v1.0.8
initial
1 CVE
CVE-2021-42576
GO-2022-0588
GHSA-x95h-979x-cf3j
PYSEC-2021-849
Aug 15, 2022
Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing. Fixed in
1.0.16
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.8
initial
Dependencies (2)
|