Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / leizongmin/js-xss issues and pull requests

#291 - Missing single quote escaping when singleQuotedAttributeValue is enabled

Issue - State: open - Opened by mdk000 2 months ago - 1 comment

#288 - How to use this packages in typescript project.

Issue - State: open - Opened by sheikharifulislam 8 months ago - 1 comment

#287 - feat: single-quoted attribute value syntax support

Pull Request - State: closed - Opened by mdk000 9 months ago - 4 comments

#285 - Merge master

Pull Request - State: closed - Opened by 123robi about 1 year ago

#284 - How to see what tags are removed?

Issue - State: open - Opened by Thomas-1985 about 1 year ago

#283 - Doesn't sanitize "<p>abc<iframe//src=jAva&Tab;script:alert(3)>def</p>"

Issue - State: open - Opened by LeanKhan over 1 year ago - 1 comment

#282 - How to whitelist cookies

Issue - State: open - Opened by ashuorg over 1 year ago

#280 - img src processed to empty

Issue - State: open - Opened by wcnjeusr over 1 year ago - 2 comments

#279 - feat: add <kbd> to default whitelist

Pull Request - State: closed - Opened by rayrny over 1 year ago - 1 comment

#278 - feat: Allow loading attribute on img

Pull Request - State: closed - Opened by maosmurf over 1 year ago

#277 - feat: Allow loading attribute on img

Pull Request - State: closed - Opened by maosmurf over 1 year ago - 1 comment

#276 - Support being imported by Node

Issue - State: open - Opened by amjmhs over 1 year ago

#274 - Cannot create xss instance with options ^1.0.14

Issue - State: open - Opened by quoctienkt almost 2 years ago

#273 - Links in href/src needs a protocol, but not in url(), why ?

Issue - State: open - Opened by sky0matic almost 2 years ago

#272 - chore: fix typo

Pull Request - State: closed - Opened by shigma almost 2 years ago

#271 - Ignore greater or less than symbol?

Issue - State: open - Opened by iamsarthakjoshi almost 2 years ago - 1 comment

#270 - feat: Add <kbd> tag to default whitelist

Pull Request - State: closed - Opened by rayrny almost 2 years ago - 3 comments

#269 - Fix slashes as separators.

Pull Request - State: open - Opened by hensleysecurity almost 2 years ago - 2 comments

#267 - Escaping attribute does not work sufficient

Issue - State: open - Opened by djschilling almost 2 years ago - 1 comment

#265 - At v1.0.14 stripIgnoreTag behavior changed

Issue - State: open - Opened by BlakeStearman about 2 years ago - 1 comment

#264 - src with blob:... is removed

Issue - State: open - Opened by tungnat97 over 2 years ago - 1 comment

#263 - video标签过滤后source标签丢失

Issue - State: open - Opened by wangkemin over 2 years ago - 2 comments

#262 - fix: problem with not closed tag

Pull Request - State: closed - Opened by slawiko over 2 years ago - 2 comments

#261 - fix: add `allowList` to types

Pull Request - State: closed - Opened by metonym over 2 years ago - 2 comments

#260 - 运算符 大于号>和小于号<不想被转码

Issue - State: open - Opened by Cossey11111 over 2 years ago - 1 comment

#259 - "invalid group specifier name" error in Safari after upgrade to 1.0.12

Issue - State: closed - Opened by scottohara over 2 years ago - 7 comments
Labels: bug

#258 - add another site that extensively uses XSS

Pull Request - State: closed - Opened by williamstein over 2 years ago

#257 - fix: comment has encoded

Pull Request - State: closed - Opened by lumburr over 2 years ago

#256 - fix: whitelist match failure due to case ignoring

Pull Request - State: closed - Opened by lumburr over 2 years ago

#255 - fix: whitelist match failure due to case ignoring

Pull Request - State: closed - Opened by lumburr over 2 years ago

#254 - fix: example whiteList type error

Pull Request - State: closed - Opened by lumburr over 2 years ago

#253 - fix #245

Pull Request - State: closed - Opened by lumburr over 2 years ago

#252 - feat: add eslint:recommended check

Pull Request - State: closed - Opened by lumburr over 2 years ago

#249 - feat: add support for allowList as an alias for whiteList

Pull Request - State: closed - Opened by schu34 almost 3 years ago - 6 comments

#248 - 单纯一份JS,如何设置css 为false?

Issue - State: open - Opened by AceChen1 about 3 years ago - 2 comments

#247 - whiteList does nothing

Issue - State: open - Opened by chladnefazole about 3 years ago - 1 comment

#246 - fix(general): problem with double value in class

Pull Request - State: closed - Opened by sh4d0q about 3 years ago - 1 comment

#245 - class is wrong separated by attributes in method onTagAttr

Issue - State: closed - Opened by sh4d0q about 3 years ago - 13 comments

#244 - How can I remove [removed] text from stripIgnoreTagBody: ['script'] option?

Issue - State: open - Opened by amjadaliup about 3 years ago - 2 comments

#243 - <vedio><source .... ></vedio> is not sanitised properly.

Issue - State: open - Opened by UD-UD about 3 years ago - 1 comment

#241 - new line characters filtered out

Issue - State: closed - Opened by ittybittykitty about 3 years ago - 1 comment

#239 - [Security] Fix ReDoS

Pull Request - State: closed - Opened by ready-research about 3 years ago - 3 comments

#238 - Trying to get in touch regarding a security issue

Issue - State: closed - Opened by JamieSlome about 3 years ago - 1 comment

#237 - 富文本引入xss后,正常的删除线标签未能被解析

Issue - State: open - Opened by xjsdlla about 3 years ago - 1 comment

#236 - improve safeAttrValue function

Pull Request - State: closed - Opened by madneal over 3 years ago - 3 comments

#235 - Commander version doesn't exist

Issue - State: closed - Opened by MMMikeM over 3 years ago - 2 comments

#234 - why i use xssFilter({ css: false }) is not take effect?

Issue - State: open - Opened by caoyanxuan over 3 years ago - 3 comments

#231 - 提供选项允许校验标签的完整性?

Issue - State: open - Opened by undefined-moe over 3 years ago - 5 comments

#230 - HTML comment tags are encoded

Issue - State: closed - Opened by andrey-skl over 3 years ago - 3 comments

#229 - [Question] How to use typings in browser-targeting code?

Issue - State: closed - Opened by marekdedic over 3 years ago - 2 comments

#228 - 如何设置某些标签不处理?使用wangeditor编辑器

Issue - State: closed - Opened by y1324 over 3 years ago - 1 comment

#226 - Doesnt support strike tag in whitelist for typescript

Issue - State: closed - Opened by mixalbl4-127 over 3 years ago - 1 comment

#225 - Self-closing tags doesnt make "isClosing" as true

Issue - State: open - Opened by mixalbl4-127 over 3 years ago

#224 - No onTag options in TypeScript types

Issue - State: open - Opened by mixalbl4-127 over 3 years ago - 1 comment

#223 - Add custom tag filter case to doc

Issue - State: open - Opened by Kolobok12309 over 3 years ago - 1 comment

#222 - docs: correct empty whiteList typing in examples

Pull Request - State: closed - Opened by aprilandjan almost 4 years ago

#221 - add allowed schemes for URLS. eg, http:// https:// mailto: tel: sms:

Issue - State: open - Opened by amit777 almost 4 years ago - 1 comment

#220 - Add <figure> and <figcaption> to default whitelist

Pull Request - State: closed - Opened by daraz999 almost 4 years ago - 1 comment

#219 - [Discussion] Usage of the term "whitelist"

Issue - State: open - Opened by JonHX almost 4 years ago - 4 comments

#218 - Fix whitespace bypass

Pull Request - State: closed - Opened by TomAnthony almost 4 years ago

#217 - Progress tag

Issue - State: open - Opened by jerod33 almost 4 years ago - 1 comment

#216 - Add `<summary>` to default whitelist

Pull Request - State: closed - Opened by spacegaier almost 4 years ago - 6 comments

#215 - How to check input string is vulnerable

Issue - State: open - Opened by sozakir almost 4 years ago - 1 comment

#214 - Whitelist a tag with any attribute

Issue - State: closed - Opened by AdrianNeatu almost 4 years ago - 3 comments

#213 - 11

Issue - State: closed - Opened by frontendwq about 4 years ago

#212 - Event handler attributes not sanitized

Issue - State: open - Opened by skitterm about 4 years ago

#211 - Filter style tag content

Issue - State: open - Opened by klukackova about 4 years ago - 2 comments

#210 - Filtering style tag value

Issue - State: closed - Opened by klukackova about 4 years ago

#209 - Feature request isXss(value)

Issue - State: open - Opened by Cariaga about 4 years ago - 1 comment

#208 - TypeScript error when using plain text example

Issue - State: open - Opened by jthomerson about 4 years ago - 1 comment

#206 - Update README.md

Pull Request - State: closed - Opened by vais about 4 years ago

#205 - Allow only certain items in an attribute?

Issue - State: open - Opened by jpacitto-stratus about 4 years ago

#204 - docs: Fix simple typo, doube -> double

Pull Request - State: closed - Opened by timgates42 about 4 years ago - 1 comment

#202 - Fix Documentation Example

Pull Request - State: closed - Opened by swseverance over 4 years ago - 2 comments

#201 - Update handling of quoteStart to prevent sanitization bypass

Pull Request - State: closed - Opened by TomAnthony over 4 years ago - 1 comment

#200 - Allow default imports in TS

Pull Request - State: closed - Opened by danvk over 4 years ago - 4 comments

#199 - Namespaced tags are escaped

Issue - State: closed - Opened by arildm over 4 years ago - 3 comments

#198 - Update xss.js

Pull Request - State: closed - Opened by mengpinghu over 4 years ago

#197 - Why not use DOMParser?

Issue - State: open - Opened by burtonator over 4 years ago - 1 comment

#196 - MSO tags will be escaped

Issue - State: open - Opened by Alvis-Li over 4 years ago - 5 comments

#194 - Support number 0

Issue - State: closed - Opened by zhixinpeng over 4 years ago - 1 comment

#185 - 增加属性

Issue - State: open - Opened by hackwaly almost 5 years ago - 4 comments

#184 - image src = base64 miss

Issue - State: closed - Opened by Leonard-Li777 almost 5 years ago - 2 comments

#182 - jsxss.com is not working because of lang forward rules

Issue - State: closed - Opened by sijanec about 5 years ago - 1 comment

#176 - The module encodes any < > even if they are not part of a tag

Issue - State: open - Opened by tomerb15 over 5 years ago - 2 comments