symfony/html-sanitizer
Provides an object-oriented API to sanitize untrusted HTML input for safe insertion into a document's DOM.
v8.1.1
49M downloads/mo
#270 most downloaded on Packagist
symfony/html-sanitizer
What this package is like to depend on
Last release 2 months ago
06 Jun 2026
Release timing varies
gaps range from 8 days to 4 months
Rarely documented
notes for 8 of 61 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
89 releases · first in 2022
24 releases in the last 12 months
see the full history below
Release timeline
70 releases · Feb 2022 to Jun 2026Releases
latest 60 of 89-
v8.1.106 Jun 2026Release notes
Open source →Changelog (v8.1.0...v8.1.1)
- minor #64524 Make tests compatible with PHPUnit 13.2 and Twig 3.28 (@nicolas-grekas)
-
v8.1.029 May 2026 -
v8.1.0-RC124 May 2026 pre-releaseRelease notes
Open source →Changelog (v8.1.0-BETA3...v8.1.0-RC1)
- security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
- security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
- bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)
-
v8.1.0-BETA320 May 2026 pre-releaseRelease notes
Open source →Changelog (v8.1.0-BETA1...v8.1.0-BETA3)
- security #cve-2026-45753 Sanitize URLs in action, formaction, poster and cite attributes (@nicolas-grekas)
- security #cve-2026-45064 Reject BiDi override characters and percent-encode spaces in URLs (@nicolas-grekas)
- security #cve-2026-45066 Fix
allowLinkHosts/allowMediaHostsbypass via URL parser differentials and<area>misclassification (@alexandre-daubois)
-
v8.1.0-BETA118 Apr 2026 pre-releaseNothing published for this version
-
v8.0.1406 Jun 2026Release notes
Open source →Changelog (v8.0.13...v8.0.14)
- minor #64524 Make tests compatible with PHPUnit 13.2 and Twig 3.28 (@nicolas-grekas)
-
v8.0.1324 May 2026Release notes
Open source →Changelog (v8.0.12...v8.0.13)
- security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
- security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
- bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)
-
v8.0.1220 May 2026Release notes
Open source →Changelog (v8.0.7...v8.0.12)
- security #cve-2026-45753 Sanitize URLs in action, formaction, poster and cite attributes (@nicolas-grekas)
- security #cve-2026-45064 Reject BiDi override characters and percent-encode spaces in URLs (@nicolas-grekas)
- security #cve-2026-45066 Fix
allowLinkHosts/allowMediaHostsbypass via URL parser differentials and<area>misclassification (@alexandre-daubois)
-
v8.0.830 Mar 2026Nothing published for this version
-
v8.0.706 Mar 2026Nothing published for this version
-
v8.0.030 Oct 2025Nothing published for this version
-
v8.0.0-RC1no date pre-releaseNothing published for this version
-
v8.0.0-BETA2no date pre-releaseNothing published for this version
-
v8.0.0-BETA101 Oct 2025 pre-releaseNothing published for this version
-
v7.4.1406 Jun 2026Release notes
Open source →Changelog (v7.4.13...v7.4.14)
- minor #64524 Make tests compatible with PHPUnit 13.2 and Twig 3.28 (@nicolas-grekas)
-
v7.4.1324 May 2026Release notes
Open source →Changelog (v7.4.12...v7.4.13)
- security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
- security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
- bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)
-
v7.4.1220 May 2026Nothing published for this version
-
v7.4.824 Mar 2026Nothing published for this version
-
v7.4.706 Mar 2026Nothing published for this version
-
v7.4.030 Oct 2025Nothing published for this version
-
v7.4.0-RC1no date pre-releaseNothing published for this version
-
v7.4.0-BETA2no date pre-releaseNothing published for this version
-
v7.4.0-BETA101 Oct 2025 pre-releaseNothing published for this version
-
v7.3.630 Oct 2025Nothing published for this version
-
v7.3.312 Aug 2025Nothing published for this version
-
v7.3.210 Jul 2025Nothing published for this version
-
v7.3.031 Mar 2025Nothing published for this version
-
v7.3.0-RC1no date pre-releaseNothing published for this version
-
v7.3.0-BETA1no date pre-releaseNothing published for this version
-
v7.2.910 Jul 2025Nothing published for this version
-
v7.2.631 Mar 2025Nothing published for this version
-
v7.2.327 Jan 2025Nothing published for this version
-
v7.2.230 Dec 2024Nothing published for this version
-
v7.2.025 Sep 2024Nothing published for this version
-
v7.2.0-RC1no date pre-releaseNothing published for this version
-
v7.2.0-BETA1no date pre-releaseNothing published for this version
-
v7.1.1127 Jan 2025Nothing published for this version
-
v7.1.1030 Dec 2024Nothing published for this version
-
v7.1.625 Sep 2024Nothing published for this version
-
v7.1.520 Sep 2024Nothing published for this version
-
v7.1.131 May 2024Nothing published for this version
-
v7.1.018 Apr 2024Nothing published for this version
-
v7.1.0-RC1no date pre-releaseNothing published for this version
-
v7.1.0-BETA1no date pre-releaseNothing published for this version
-
v7.0.831 May 2024Nothing published for this version
-
v7.0.718 Apr 2024Nothing published for this version
-
v7.0.415 Feb 2024Nothing published for this version
-
v7.0.323 Jan 2024Nothing published for this version
-
v7.0.028 Oct 2023Nothing published for this version
-
v7.0.0-RC1no date pre-releaseNothing published for this version
-
v7.0.0-BETA2no date pre-releaseNothing published for this version
-
v7.0.0-BETA119 Oct 2023 pre-releaseNothing published for this version
-
v6.4.4124 May 2026Release notes
Open source →Changelog (v6.4.40...v6.4.41)
- security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
- security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
- bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)
-
v6.4.4019 May 2026Nothing published for this version
-
v6.4.3506 Mar 2026Nothing published for this version
-
v6.4.2829 Oct 2025Nothing published for this version
-
v6.4.2512 Aug 2025Nothing published for this version
-
v6.4.2410 Jul 2025Nothing published for this version
-
v6.4.2131 Mar 2025Nothing published for this version
-
v6.4.1817 Jan 2025Nothing published for this version