Loading
Generated remediation guidance and an executive summary. No account required.
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.
Use CWE-79, Apostrophecms vendor hub and Sanitize-Html product page to widen CVE-2019-25225 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40186, CVE-2014-125128 and CVE-2016-1000237 for nearby disclosures in the same product family.