๐Ÿ” CVE Alert

CVE-2026-47344

UNKNOWN 0.0

TYPO3 HTML Sanitizer allows Cross-Site Scripting

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

CWE CWE-79 CWE-436
Vendor typo3
Product html sanitizer
Published Jun 8, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 html sanitizer

Be the first to know when new unknown vulnerabilities affecting typo3 html sanitizer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / HTML Sanitizer
0 < 2.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2026-006 github.com: https://github.com/TYPO3/html-sanitizer/commit/bd1a88d9b5a5f67f1120ec41084e9c1a0675641c

Credits

๐Ÿ” IPC Labs Oliver Hader