CVE-2026-47345EPSS p35.8%
CVE-2026-47345CVE-2026-47345
Description
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Scoring
| EPSS | 0.44% probability of exploitation · percentile 35.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-23 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.