📦

bluemonday

Vendor: microco

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 1.22% Exploit Prob.
Latest CVE CVE-2021-42576 Oct 18

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

EPSS: 1.51%
6.1 CVSS

bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.

EPSS: 0.93%