justhtml has 11 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 5 in the 90 before. The busiest recent month was March 2026 with 4. The median CVSS is 6.1 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 5
Worst active — by depth score
CVE-2026-5389HighJustHTML is vulnerable to XSS via code fence breakout in <pre> content41CVE-2026-9769HighUncontrolled recursion DoS in JustHTML() via deeply nested HTML41GHSA-jf6w-2mvx-633jMedium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS34CVE-2026-77088Medium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS34CVE-2026-6827Mediumjusthtml has sanitization bypass in custom policies and programmatic DOM28
justhtml vulnerabilities
CVEs affecting justhtml, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-77088Medium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS
GHSA-jf6w-2mvx-633jMedium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS
CVE-2026-4671Lowjusthtml introduces denial-of-service hardening
justhtml introduces denial-of-service hardening
CVE-2026-6827Mediumjusthtml has sanitization bypass in custom policies and programmatic DOM
justhtml has sanitization bypass in custom policies and programmatic DOM
CVE-2026-7808LowMultiple security fixes in justhtml
Multiple security fixes in justhtml
CVE-2026-5388Mediumjusthtml includes multiple security fixes
justhtml includes multiple security fixes
CVE-2026-5751Lowjusthtml: Mutation XSS with custom foreign-namespace sanitization policies
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
CVE-2026-5389HighJustHTML is vulnerable to XSS via code fence breakout in <pre> content
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
CVE-2026-8630MediumJustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
CVE-2026-8445MediumJustHTML has a Sanitizer Bypass (in Markdown)
JustHTML has a Sanitizer Bypass (in Markdown)
CVE-2026-9769HighUncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML