CVE-2026-61784

CVE-2026-61784 published: xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifi...

View full NVD advisory → ← Back to CVE watch