Ecosyste.ms: Issues
An open API service for providing issue and pull request metadata for open source projects.
GitHub / leizongmin/js-xss issues and pull requests
#291 - Missing single quote escaping when singleQuotedAttributeValue is enabled
Issue -
State: open - Opened by mdk000 2 months ago
- 1 comment
#290 - fix: add single quote escaping when singleQuotedAttributeValue is enabled
Pull Request -
State: open - Opened by mdk000 2 months ago
#288 - How to use this packages in typescript project.
Issue -
State: open - Opened by sheikharifulislam 8 months ago
- 1 comment
#287 - feat: single-quoted attribute value syntax support
Pull Request -
State: closed - Opened by mdk000 9 months ago
- 4 comments
#286 - Is it possible to preserve case on attributes when filtering XSS?
Issue -
State: open - Opened by ok-martin 9 months ago
#285 - Merge master
Pull Request -
State: closed - Opened by 123robi about 1 year ago
#284 - How to see what tags are removed?
Issue -
State: open - Opened by Thomas-1985 about 1 year ago
#283 - Doesn't sanitize "<p>abc<iframe//src=jAva	script:alert(3)>def</p>"
Issue -
State: open - Opened by LeanKhan over 1 year ago
- 1 comment
#282 - How to whitelist cookies
Issue -
State: open - Opened by ashuorg over 1 year ago
#281 - a标签已经被加入到了白名a: ['class', 'href', 'target'],但是href里面放入自定义协议,比如baidu360://efwefwfwe给过滤了,怎么办
Issue -
State: open - Opened by daweiyong over 1 year ago
- 1 comment
#280 - img src processed to empty
Issue -
State: open - Opened by wcnjeusr over 1 year ago
- 2 comments
#279 - feat: add <kbd> to default whitelist
Pull Request -
State: closed - Opened by rayrny over 1 year ago
- 1 comment
#278 - feat: Allow loading attribute on img
Pull Request -
State: closed - Opened by maosmurf over 1 year ago
#277 - feat: Allow loading attribute on img
Pull Request -
State: closed - Opened by maosmurf over 1 year ago
- 1 comment
#276 - Support being imported by Node
Issue -
State: open - Opened by amjmhs over 1 year ago
#275 - The href content in a tag is 'data: image', which is not processed
Issue -
State: open - Opened by qsy0213 almost 2 years ago
#274 - Cannot create xss instance with options ^1.0.14
Issue -
State: open - Opened by quoctienkt almost 2 years ago
#273 - Links in href/src needs a protocol, but not in url(), why ?
Issue -
State: open - Opened by sky0matic almost 2 years ago
#272 - chore: fix typo
Pull Request -
State: closed - Opened by shigma almost 2 years ago
#271 - Ignore greater or less than symbol?
Issue -
State: open - Opened by iamsarthakjoshi almost 2 years ago
- 1 comment
#270 - feat: Add <kbd> tag to default whitelist
Pull Request -
State: closed - Opened by rayrny almost 2 years ago
- 3 comments
#269 - Fix slashes as separators.
Pull Request -
State: open - Opened by hensleysecurity almost 2 years ago
- 2 comments
#268 - whiteList fails when using slashes to separate tag attributes (PR included)
Issue -
State: open - Opened by hensleysecurity almost 2 years ago
#267 - Escaping attribute does not work sufficient
Issue -
State: open - Opened by djschilling almost 2 years ago
- 1 comment
#266 - I would like to know why all styles need to be whitelisted by configuration before they are not filtered?
Issue -
State: open - Opened by XiaoRIGE almost 2 years ago
#265 - At v1.0.14 stripIgnoreTag behavior changed
Issue -
State: open - Opened by BlakeStearman about 2 years ago
- 1 comment
#264 - src with blob:... is removed
Issue -
State: open - Opened by tungnat97 over 2 years ago
- 1 comment
#263 - video标签过滤后source标签丢失
Issue -
State: open - Opened by wangkemin over 2 years ago
- 2 comments
#262 - fix: problem with not closed tag
Pull Request -
State: closed - Opened by slawiko over 2 years ago
- 2 comments
#261 - fix: add `allowList` to types
Pull Request -
State: closed - Opened by metonym over 2 years ago
- 2 comments
#260 - 运算符 大于号>和小于号<不想被转码
Issue -
State: open - Opened by Cossey11111 over 2 years ago
- 1 comment
#259 - "invalid group specifier name" error in Safari after upgrade to 1.0.12
Issue -
State: closed - Opened by scottohara over 2 years ago
- 7 comments
Labels: bug
#258 - add another site that extensively uses XSS
Pull Request -
State: closed - Opened by williamstein over 2 years ago
#257 - fix: comment has encoded
Pull Request -
State: closed - Opened by lumburr over 2 years ago
#256 - fix: whitelist match failure due to case ignoring
Pull Request -
State: closed - Opened by lumburr over 2 years ago
#255 - fix: whitelist match failure due to case ignoring
Pull Request -
State: closed - Opened by lumburr over 2 years ago
#254 - fix: example whiteList type error
Pull Request -
State: closed - Opened by lumburr over 2 years ago
#253 - fix #245
Pull Request -
State: closed - Opened by lumburr over 2 years ago
#252 - feat: add eslint:recommended check
Pull Request -
State: closed - Opened by lumburr over 2 years ago
#251 - Confusing variable assignment - Eslint should be configured for this project
Issue -
State: open - Opened by ctaschereau over 2 years ago
- 2 comments
#250 - 可不可以设置一个黑名单除了黑名单里面的标签剩余都是白名单
Issue -
State: open - Opened by Lrunlin almost 3 years ago
#249 - feat: add support for allowList as an alias for whiteList
Pull Request -
State: closed - Opened by schu34 almost 3 years ago
- 6 comments
#248 - 单纯一份JS,如何设置css 为false?
Issue -
State: open - Opened by AceChen1 about 3 years ago
- 2 comments
#247 - whiteList does nothing
Issue -
State: open - Opened by chladnefazole about 3 years ago
- 1 comment
#246 - fix(general): problem with double value in class
Pull Request -
State: closed - Opened by sh4d0q about 3 years ago
- 1 comment
#245 - class is wrong separated by attributes in method onTagAttr
Issue -
State: closed - Opened by sh4d0q about 3 years ago
- 13 comments
#244 - How can I remove [removed] text from stripIgnoreTagBody: ['script'] option?
Issue -
State: open - Opened by amjadaliup about 3 years ago
- 2 comments
#243 - <vedio><source .... ></vedio> is not sanitised properly.
Issue -
State: open - Opened by UD-UD about 3 years ago
- 1 comment
#242 - Question: is there a way to, when stripping tags, replace them with spaces?
Issue -
State: open - Opened by KayakinKoder about 3 years ago
- 1 comment
#241 - new line characters filtered out
Issue -
State: closed - Opened by ittybittykitty about 3 years ago
- 1 comment
#240 - 一样的过滤选项及内容,开发环境和编译后的输出有区别,编译后的第一个标签的起始标签被转义了
Issue -
State: open - Opened by alvawu about 3 years ago
- 3 comments
#239 - [Security] Fix ReDoS
Pull Request -
State: closed - Opened by ready-research about 3 years ago
- 3 comments
#238 - Trying to get in touch regarding a security issue
Issue -
State: closed - Opened by JamieSlome about 3 years ago
- 1 comment
#237 - 富文本引入xss后,正常的删除线标签未能被解析
Issue -
State: open - Opened by xjsdlla about 3 years ago
- 1 comment
#236 - improve safeAttrValue function
Pull Request -
State: closed - Opened by madneal over 3 years ago
- 3 comments
#235 - Commander version doesn't exist
Issue -
State: closed - Opened by MMMikeM over 3 years ago
- 2 comments
#234 - why i use xssFilter({ css: false }) is not take effect?
Issue -
State: open - Opened by caoyanxuan over 3 years ago
- 3 comments
#233 - option 中存在 img: ["src"] 选项 但是转完之后图片显示 <img src=(unknow)>
Issue -
State: closed - Opened by liuyaoShuai over 3 years ago
#232 - 请问是否不能保留CSS样式?如果富文本编辑的内容有行内样式的话
Issue -
State: closed - Opened by femaimi9527 over 3 years ago
- 2 comments
#231 - 提供选项允许校验标签的完整性?
Issue -
State: open - Opened by undefined-moe over 3 years ago
- 5 comments
#230 - HTML comment tags are encoded
Issue -
State: closed - Opened by andrey-skl over 3 years ago
- 3 comments
#229 - [Question] How to use typings in browser-targeting code?
Issue -
State: closed - Opened by marekdedic over 3 years ago
- 2 comments
#228 - 如何设置某些标签不处理?使用wangeditor编辑器
Issue -
State: closed - Opened by y1324 over 3 years ago
- 1 comment
#227 - [Question] Why the `muted` attribute of the `video` tag not in the default whitelist?
Issue -
State: closed - Opened by maltoze over 3 years ago
- 1 comment
#226 - Doesnt support strike tag in whitelist for typescript
Issue -
State: closed - Opened by mixalbl4-127 over 3 years ago
- 1 comment
#225 - Self-closing tags doesnt make "isClosing" as true
Issue -
State: open - Opened by mixalbl4-127 over 3 years ago
#224 - No onTag options in TypeScript types
Issue -
State: open - Opened by mixalbl4-127 over 3 years ago
- 1 comment
#223 - Add custom tag filter case to doc
Issue -
State: open - Opened by Kolobok12309 over 3 years ago
- 1 comment
#222 - docs: correct empty whiteList typing in examples
Pull Request -
State: closed - Opened by aprilandjan almost 4 years ago
#221 - add allowed schemes for URLS. eg, http:// https:// mailto: tel: sms:
Issue -
State: open - Opened by amit777 almost 4 years ago
- 1 comment
#220 - Add <figure> and <figcaption> to default whitelist
Pull Request -
State: closed - Opened by daraz999 almost 4 years ago
- 1 comment
#219 - [Discussion] Usage of the term "whitelist"
Issue -
State: open - Opened by JonHX almost 4 years ago
- 4 comments
#218 - Fix whitespace bypass
Pull Request -
State: closed - Opened by TomAnthony almost 4 years ago
#217 - Progress tag
Issue -
State: open - Opened by jerod33 almost 4 years ago
- 1 comment
#216 - Add `<summary>` to default whitelist
Pull Request -
State: closed - Opened by spacegaier almost 4 years ago
- 6 comments
#215 - How to check input string is vulnerable
Issue -
State: open - Opened by sozakir almost 4 years ago
- 1 comment
#214 - Whitelist a tag with any attribute
Issue -
State: closed - Opened by AdrianNeatu almost 4 years ago
- 3 comments
#213 - 11
Issue -
State: closed - Opened by frontendwq about 4 years ago
#212 - Event handler attributes not sanitized
Issue -
State: open - Opened by skitterm about 4 years ago
#211 - Filter style tag content
Issue -
State: open - Opened by klukackova about 4 years ago
- 2 comments
#210 - Filtering style tag value
Issue -
State: closed - Opened by klukackova about 4 years ago
#209 - Feature request isXss(value)
Issue -
State: open - Opened by Cariaga about 4 years ago
- 1 comment
#208 - TypeScript error when using plain text example
Issue -
State: open - Opened by jthomerson about 4 years ago
- 1 comment
#207 - 如果不对<pre>, <code>代码块里的标签不做处理,例如可以输入<input>
Issue -
State: open - Opened by wxydigua about 4 years ago
#206 - Update README.md
Pull Request -
State: closed - Opened by vais about 4 years ago
#205 - Allow only certain items in an attribute?
Issue -
State: open - Opened by jpacitto-stratus about 4 years ago
#204 - docs: Fix simple typo, doube -> double
Pull Request -
State: closed - Opened by timgates42 about 4 years ago
- 1 comment
#203 - Preserve text content (document data) for ignored tags (removing all child tags).
Issue -
State: open - Opened by josundt over 4 years ago
#202 - Fix Documentation Example
Pull Request -
State: closed - Opened by swseverance over 4 years ago
- 2 comments
#201 - Update handling of quoteStart to prevent sanitization bypass
Pull Request -
State: closed - Opened by TomAnthony over 4 years ago
- 1 comment
#200 - Allow default imports in TS
Pull Request -
State: closed - Opened by danvk over 4 years ago
- 4 comments
#199 - Namespaced tags are escaped
Issue -
State: closed - Opened by arildm over 4 years ago
- 3 comments
#198 - Update xss.js
Pull Request -
State: closed - Opened by mengpinghu over 4 years ago
#197 - Why not use DOMParser?
Issue -
State: open - Opened by burtonator over 4 years ago
- 1 comment
#196 - MSO tags will be escaped
Issue -
State: open - Opened by Alvis-Li over 4 years ago
- 5 comments
#194 - Support number 0
Issue -
State: closed - Opened by zhixinpeng over 4 years ago
- 1 comment
#185 - 增加属性
Issue -
State: open - Opened by hackwaly almost 5 years ago
- 4 comments
#184 - image src = base64 miss
Issue -
State: closed - Opened by Leonard-Li777 almost 5 years ago
- 2 comments
#182 - jsxss.com is not working because of lang forward rules
Issue -
State: closed - Opened by sijanec about 5 years ago
- 1 comment
#176 - The module encodes any < > even if they are not part of a tag
Issue -
State: open - Opened by tomerb15 over 5 years ago
- 2 comments