sanitize-html before 1.4.3 has XSS.
| Software | From | Fixed in |
|---|---|---|
| apostrophecms / sanitize-html | - | 1.4.3 |
sanitize-html
|
- | 1.4.3 |