0.002 Low
EPSS
Percentile
59.1%
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
bugzilla.redhat.com/show_bug.cgi?id=1827491