Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-8630: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtmlCVE-2026-8630
0

justhtml versions up to 1.11.0 contain a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements like <style> and <script>. This occurs when using a custom sanitization policy that retains these elements, allowing attacker-controlled text to inject arbitrary HTML. The default sanitization policy is not affected as it removes the contents of these elements.

Join the discussion
CVE-2026-8445: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtmlCVE-2026-8445
0

justhtml versions up to 1.11.0 have a cross-site scripting (XSS) vulnerability due to improper escaping of HTML-significant characters in Markdown output. This allows untrusted input containing certain HTML entities or text from specific HTML elements to be rendered as raw HTML, potentially bypassing sanitizers and enabling XSS attacks. The issue is fixed in version 1.12.0.

Join the discussion
CVE-2026-7808: Improper Input Validation in EmilStenstrom justhtmlCVE-2026-7808
0

justhtml before version 1.16.0 contains multiple HTML sanitization bypass vulnerabilities that can allow dangerous active content such as scripts or styles to survive sanitization, potentially leading to cross-site scripting (XSS). These issues mainly affect advanced usage scenarios involving mutation or reuse of sanitization policies, programmatic DOM input with mixed-case tags, crafted doctype names, and custom policies preserving SVG or MathML content. The vulnerabilities were fixed in version 1.16.0.

Join the discussion
CVE-2026-77088: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtmlCVE-2026-77088
0

justhtml versions 0.9.0 through 1.21.0 have a cross-site scripting (XSS) vulnerability in the to_markdown() function. This occurs because inline code spans do not properly handle blank lines as block boundaries, allowing attackers to inject blank lines that break the inline span. As a result, sanitized HTML can be emitted unescaped and re-parsed as live Markdown by compliant renderers, potentially leading to XSS attacks.

Join the discussion
CVE-2026-74793: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtmlCVE-2026-74793
0

justhtml versions prior to 3.11.0 contain a cross-site scripting (XSS) vulnerability due to improper input neutralization during web page generation. The default sanitizer fails to remove event handlers in selectedcontent projections, allowing attackers to inject SVG or MathML elements with event handlers that are cloned and reinserted without sanitization. This enables stored or reflected XSS attacks. The vulnerability has a medium severity with a CVSS score of 5.1. No patch or official remediation has been confirmed yet.

Join the discussion
CVE-2026-6827: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtmlCVE-2026-6827
0

CVE-2026-6827 is a medium severity cross-site scripting (XSS) vulnerability in EmilStenstrom justhtml before version 1.17.0. It involves improper neutralization of input during web page generation, particularly when custom policies preserve foreign namespaces like SVG and MathML. This can allow dangerous content to survive sanitization and become active HTML after reparsing. The vulnerability affects advanced or custom configurations rather than the default safe sanitization path. No official patch or remediation guidance is currently confirmed.

Join the discussion
CVE-2026-5751: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtmlCVE-2026-5751
0

justhtml versions 1.13.0 and earlier have a mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces. This vulnerability allows specially crafted input to be sanitized into markup that appears safe but becomes unsafe when re-parsed by browsers or other HTML parsers, enabling markup injection. The default safe configuration is not affected. The issue is fixed in version 1.14.0.

Join the discussion
CVE-2026-5389: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in EmilStenstrom justhtmlCVE-2026-5389
0

justhtml versions before 1.13.0 contain a cross-site scripting (XSS) vulnerability in the to_markdown() function. This occurs when serializing attacker-controlled pre content, allowing attackers to inject backticks inside sanitized pre elements. This breaks out of fixed-length code fences and enables raw HTML execution when the Markdown is rendered by CommonMark or GFM-style renderers.

Join the discussion
CVE-2026-5388: Improper Input Validation in EmilStenstrom justhtmlCVE-2026-5388
0

CVE-2026-5388 affects EmilStenstrom justhtml versions before 1.15.0 and involves multiple security issues in URL sanitization helpers, HTML serialization, Markdown passthrough, and custom sanitization policies. These issues can allow attackers to bypass sanitization and inject active HTML and JavaScript under certain configurations. The vulnerability is critical with a CVSS score of 9.3. Most issues do not affect the default sanitize=true setting but impact helper APIs, programmatic DOM construction, html_passthrough=true, and custom policies.

Join the discussion
CVE-2026-4671: Uncontrolled Resource Consumption in EmilStenstrom justhtmlCVE-2026-4671
0

CVE-2026-4671 is a high-severity denial-of-service vulnerability in EmilStenstrom justhtml before version 1.18.0. It involves uncontrolled resource consumption triggered by maliciously crafted CSS selectors and linkification inputs. The issues arise when attacker-controlled selector strings are evaluated or when large or complex selectors are processed, potentially causing excessive CPU or memory use. This vulnerability affects availability only and does not enable script execution, data leakage, or bypass of sanitization. Default usage with sanitization enabled is not expected to be vulnerable since selectors are typically controlled by application code.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/emilstenstrom/justhtml
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses