HIGH8.2CVE-2026-49825`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes from 0, < 0.4.5
HIGH8.2CVE-2026-49825`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes from 0, < 0.4.5
HIGH7.7CVE-2024-52595HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through from 0, < 0.4.0
HIGH7.7HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
from 0, < c5d816f86eb3707d72a8ecf5f3823e0daa1b3808 | from 0, < 0.4.0
MEDIUM6.1lxml-html-clean has <base> tag injection through default Cleaner configuration
from 0, < 0.4.4
MEDIUM6.1lxml-html-clean has <base> tag injection through default Cleaner configuration
from 0, < 0.4.4
MEDIUM6.1lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
from 0, < 0.4.4
MEDIUM6.1lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
from 0, < 0.4.4