loofah vulnerabilities

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments. It's built on top of Nokogiri and libxml2, so it's fast and has a nice API. Loofah excels at HTML sanitization (XSS prevention). It includes some nice HTML sanitizers, which are based on HTML5lib's whitelist, so it most likely won't make your codes less secure. (These statements have not been evaluated by Netexperts.) ActiveRecord extensions for sanitization are available in the [`loofah-activerecord` gem](https://github.com/flavorjones/loofah-activerecord).

Latest version: 2.2.3

Licenses detected

  • license: Unknown < 2.0.0, >= 0.2.0
  • license: MIT >= 2.0.0
Continuously find & fix vulnerabilities like these in your dependencies. Test and protect your applications

Direct Vulnerabilities

Known vulnerabilities in the loofah package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable versions Snyk patch Published
  • M
Cross-site Scripting (XSS)
<2.2.3 Not available 31 Oct, 2018
  • M
Cross-site Scripting (XSS)
<2.2.1 Not available 21 Mar, 2018
  • M
Cross-site Scripting (XSS)
<0.4.4 Not available 25 Dec, 2017
  • M
Cross-site Scripting (XSS)
< 0.4.6 Not available 07 Sep, 2012