mganss / HtmlSanitizer

Cleans HTML to avoid XSS attacks
MIT License
1.55k stars 200 forks source link

unable to remove something like 'onmouseup=alert(123)// #459

Closed wuuer closed 1 year ago

wuuer commented 1 year ago

unable to remove something like 'onmouseup=alert(123)//