Vulnerability Details CVE-2020-26293
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the `<style>` tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the `<style>` tag so there is no risk if you have not explicitly allowed the `<style>` tag. The problem has been fixed in version 5.0.372.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-26293
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:-
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:2.0
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.0
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.76
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.79
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.91
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.93
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.98
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.2.100
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.2.103
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.2.105
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.122
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.125
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.126
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.127
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.128
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.129
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.130
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.131
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.132
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.134
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.140
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.142
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.143
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.144
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.145
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.146
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.147
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.148
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.4.152
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.4.156
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.5.167
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.5.168
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.5.169
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.179
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.180
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.181
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.182
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.183
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.185
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.186
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.187
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.188
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.189
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.190
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.191
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.192
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.193
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.195
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.197
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.198
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.199
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.200
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.201
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.202
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.203
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.204
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.205
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.207
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.209
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.210
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.211
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.212
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.217
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.219
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.220
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.222
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.224
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.228
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.229
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.230
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.214
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.215
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.216
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.218
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.233
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.234
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.236
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.237
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.239
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.240
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.242
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.244
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.245
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.246
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.248
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.249
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.250
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.251
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.257
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.258
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.260
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.261
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.263
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.264
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.266
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.267
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.269
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.270
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.272
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.274
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.275
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.277
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.278
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.280
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.281
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.283
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.284
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.287
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.288
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.290
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.291
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.292
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.293
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.294
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.296
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.297
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.298
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.303
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.304
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.305
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.307
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.308
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.310
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.311
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.313
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.314
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.316
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.317
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.319
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.320
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.322
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.323
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.325
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.326
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.328
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.329
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.331
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.332
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.341
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.342
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.343
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.344
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.346
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.347
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.349
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.350
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.352
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.353
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.354
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.355
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.358
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.359
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.361
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.363
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.364
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.365
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.366
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.367
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.368
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.369
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.371