Critical Alert 1 Active Exploit Detected Today

CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower


← Back to CVE List

CVE-2026-47344NVD

Vulnerability Summary

When `ALLOW_INSECURE_RAW_TEXT` is enabled, whitespace-variant closing tags (e.g., `</style\\t>`) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of `typo3/html-sanitizer` before version 2.3.2.

Credits to IPC Labs for reporting this vulnerability.
Severity Level
LOW
Published Date
Jun 8, 2026
Last Modified
Jun 12, 2026
Exploitation Status
????
EPSS Score (30-Day)
0.05%Probability
Root Weakness (CWE)
N/A

External References