justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elements with event handlers that are cloned and reinserted into output without sanitization, enabling stored or reflected XSS attacks.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-23 14:16
Updated : 2026-08-26 17:10
NVD link : CVE-2026-74793
Mitre link : CVE-2026-74793
CVE.ORG link : CVE-2026-74793
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
