loofah has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 4.7 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.7
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction26GHSA-8whx-365g-h9vvLowLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references14GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons14
loofah vulnerabilities
CVEs affecting loofah, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction
Loofah: SVG `href` attribute bypasses local-reference restriction
▾ Sunlitloofah · loofahvia GHSA
GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
▾ Sunlitloofah · loofahvia GHSA
GHSA-8whx-365g-h9vvLowLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
▾ Sunlitloofah · loofahvia GHSA