{"id":"GHSA-xv6v-72hh-g6g2","summary":"Moderate severity vulnerability that affects org.owasp.antisamy:antisamy","details":"OWASP OWASP ANTISAMY version 1.5.7 and earlier contains a Cross Site Scripting (XSS) vulnerability in AntiSamy.scan() - for both SAX & DOM that can result in Cross Site Scripting.","aliases":["CVE-2018-1000643"],"modified":"2026-09-10T03:47:30.965334197Z","published":"2018-10-18T17:22:26Z","withdrawn":"2020-06-16T22:04:31Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T22:04:31Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000643"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xv6v-72hh-g6g2"}],"affected":[{"package":{"name":"org.owasp.antisamy:antisamy","ecosystem":"Maven","purl":"pkg:maven/org.owasp.antisamy/antisamy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.5.7"}]}],"versions":["1.4.2","1.4.3","1.4.4","1.4.5","1.5","1.5.1","1.5.2","1.5.3","1.5.5","1.5.6","1.5.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-xv6v-72hh-g6g2/GHSA-xv6v-72hh-g6g2.json"}}],"schema_version":"1.9.0"}