CVE detail
CVE-2021-23980 — CVE-2021-23980
Published 2023-02-16 · Modified 2026-06-17 · Vendor mozilla · Product bleach · Source nvd
MEDIUM
severity
CVSS-derived band
0.0048
EPSS probability
exploitation probability, 30d
39.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References