CVE-2026-25543
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
04/02/2026
Last modified:
04/02/2026
Description
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM



