CVE-2026-47345
TYPO3 HTML Sanitizer allows Cross-Site Scripting
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
| CWE | CWE-79 |
| Vendor | typo3 |
| Product | html sanitizer |
| Published | Jun 8, 2026 |
| Last Updated | Jun 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 html sanitizer
Be the first to know when new unknown vulnerabilities affecting typo3 html sanitizer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TYPO3 / HTML Sanitizer
0 < 2.3.2
References
Credits
๐ Doyensec in collaboration with Claude and Anthropic Research Benjamin Franzke