Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 justhtml versions before 1.12.0 contain a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements like <style> and <script>. This occurs when a custom sanitization policy that retains these elements is used, allowing attacker-controlled text to break out of the raw-text context and inject arbitrary HTML. The default sanitization policy is not affected as it removes the contents of style and script elements. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:14 UTC Added: 08/23/2026, 13:52:40 UTC |
0 justhtml versions up to 1.11.0 have a cross-site scripting (XSS) vulnerability due to insufficient escaping of HTML-significant characters in Markdown output. This allows untrusted input containing entity-decoded text or content from certain HTML elements to be emitted as raw HTML, potentially bypassing sanitizers and enabling XSS when rendered. The issue is fixed in version 1.12.0. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:13 UTC Added: 08/23/2026, 13:52:39 UTC |
justhtml versions prior to 1.16.0 contain multiple HTML sanitization bypass vulnerabilities that may allow active content such as scripts or styles to survive sanitization, potentially leading to cross-site scripting (XSS). These issues mainly affect advanced usage scenarios involving mutation or reuse of sanitization policies, programmatic DOM inputs with mixed-case tags, crafted doctype names, and custom policies preserving SVG or MathML content. The vulnerabilities are fixed in version 1.16.0. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:13 UTC Added: 08/23/2026, 13:52:39 UTC |
0 justhtml versions 0.9.0 through 1.21.0 have a cross-site scripting (XSS) vulnerability in the to_markdown() function. This occurs because inline code spans do not properly handle blank lines as block boundaries, allowing attackers to inject blank lines into code or pre element text. This causes sanitized HTML to be emitted unescaped and re-parsed as live Markdown by compliant renderers, potentially leading to XSS attacks. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:12 UTC Added: 08/23/2026, 13:52:39 UTC |
0 justhtml versions before 3.11.0 contain a cross-site scripting (XSS) vulnerability due to improper input neutralization during web page generation. The default sanitizer fails to remove event handlers in selectedcontent projections, allowing attackers to inject SVG or MathML elements with event handlers that are cloned and reinserted without sanitization. This enables stored or reflected XSS attacks. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:11 UTC Added: 08/23/2026, 13:52:39 UTC |
0 CVE-2026-6827 is a medium severity cross-site scripting (XSS) vulnerability in EmilStenstrom justhtml versions before 1.17.0. It involves improper input neutralization during web page generation, particularly when custom sanitization policies preserve foreign namespaces like SVG and MathML. This can allow dangerous content such as SVG <foreignObject> and MathML <annotation-xml> elements to bypass sanitization and become active HTML after reparsing. Additional issues include resource-loading CSS via SVG filters and preserved <style> tags, as well as serialization of script/style/Comment nodes into active markup. These issues mainly affect advanced or custom configurations rather than the default safe sanitization path. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:11 UTC Added: 08/23/2026, 13:52:39 UTC |
0 justhtml versions 1.13.0 and earlier have a mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces. This vulnerability allows specially crafted input to be sanitized into markup that appears safe but becomes unsafe when re-parsed by a browser or another HTML parser, enabling markup injection. The default safe configuration is not affected. The issue is fixed in version 1.14.0. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:10 UTC Added: 08/23/2026, 13:52:39 UTC |
0 justhtml versions before 1.13.0 have a cross-site scripting (XSS) vulnerability in the to_markdown() function. This flaw allows attackers to inject backticks inside sanitized pre elements, breaking out of fixed-length code fences and enabling execution of raw HTML when rendered by CommonMark or GitHub Flavored Markdown (GFM) renderers. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:09 UTC Added: 08/23/2026, 13:52:39 UTC |
justhtml versions before 1.15.0 have multiple security issues related to improper input validation in URL sanitization helpers, HTML serialization, Markdown passthrough, and custom sanitization policies. These issues can allow attackers to bypass sanitization and inject active HTML and JavaScript, potentially leading to cross-site scripting (XSS) vulnerabilities. The default sanitize=true configuration is mostly unaffected; the vulnerabilities primarily impact custom policies, helper APIs, programmatic DOM construction, and html_passthrough=true settings. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:09 UTC Added: 08/23/2026, 13:52:39 UTC |
justhtml versions prior to 1.18.0 contain multiple low-severity denial-of-service vulnerabilities related to CSS selector handling and linkification. These issues can cause excessive CPU or memory consumption when processing attacker-controlled selectors or text, potentially impacting availability. The vulnerabilities do not enable script execution, data leakage, or sanitizer bypass. Default usage with sanitization enabled is not expected to be vulnerable since selectors are typically controlled by application code. Join the discussion | CVE Database V5 | 08/23/2026, 13:34:08 UTC Added: 08/23/2026, 13:52:39 UTC |
Showing 1 to 10 of 10 results