CVE-2017-16016: Punkave Sanitize-Html

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability.

Affected products

  • Punkave Sanitize-Html: up to and including 1.11.1

Published 2018-06-04. Last modified 2026-06-17.