Description
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes
Recommendation
Update the phoenix_html package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.4
- Patched version(s): 3.0.4
References
Could your website be exposed too?
SmartScanner can check your website for phoenix_html allows Cross-site Scripting in HEEx class attributes and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS) - CVE-2025-27109
- Cross-site Scripting in quill - CVE-2021-3163
- Docsify vulnerable to cross-site scripting due to mishandled encoding - CVE-2021-30074
- Cross-site Scripting in Froala Editor - froala-editor - CVE-2021-30109
You might also like:
See something that needs correcting? Let us knowUpdated April 06, 2023


