Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7889 | JS Html Sanitizer allows XSS when used with contentEditable |
Github GHSA |
GHSA-vhv4-fh94-jm5x | JS Html Sanitizer allows XSS when used with contentEditable |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 14 Mar 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when the sanitizer is used with a `contentEditable` element to set the elements `innerHTML` to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier, that runs AFTER sanitation. The issue is patched in version 2.0.3. | |
| Title | HtmlSanitizer vulnerable to XSS when used with contentEditable | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-18T14:26:06.976Z
Reserved: 2025-03-11T14:23:00.474Z
Link: CVE-2025-29771
Updated: 2025-03-18T14:25:29.356Z
Status : Deferred
Published: 2025-03-14T19:15:48.847
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-29771
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA