Vulnerability record · CVE-2019-25225 · published 8 September 2025
CVE-2019-25225: Apostrophecms sanitize-html cross-site scripting vulnerability
Apostrophecms · Sanitize Html
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.
Description
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2019/CVE-2019-25225 | ExploitThird Party Advisory |
| https://github.com/apostrophecms/sanitize-html/commit/712cb6895825c8bb6ede71a16b42bade42abcaf3 | Patch |
| https://github.com/apostrophecms/sanitize-html/issues/293 | Issue TrackingVendor Advisory |
| https://github.com/apostrophecms/sanitize-html/pull/156 | Issue TrackingPatch |
Track CVE-2019-25225 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-25225), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.