๐Ÿ” CVE Alert

CVE-2026-47345

UNKNOWN 0.0

TYPO3 HTML Sanitizer allows Cross-Site Scripting

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

CWE CWE-79
Vendor typo3
Product html sanitizer
Published Jun 8, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 html sanitizer

Be the first to know when new unknown vulnerabilities affecting typo3 html sanitizer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / HTML Sanitizer
0 < 2.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2026-006 github.com: https://github.com/TYPO3/html-sanitizer/commit/8b5d0be44ded457ca993ec9ca93d859941c63764

Credits

๐Ÿ” Doyensec in collaboration with Claude and Anthropic Research Benjamin Franzke