Loading
Generated remediation guidance and an executive summary. No account required.
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings.
Use CWE-79, Apostrophecms vendor hub and Sanitize-Html product page to widen CVE-2014-125128 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40186, CVE-2019-25225 and CVE-2016-1000237 for nearby disclosures in the same product family.