Loading
Generated remediation guidance and an executive summary. No account required.
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
Use Apostrophecms vendor hub and Sanitize-Html product page to widen CVE-2021-26540 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40186, CVE-2014-125128 and CVE-2019-25225 for nearby disclosures in the same product family.