CVE-2026-30919: Php Insecure Htmlspecialchars Noquotes
Using `htmlspecialchars()` with the `ENT_NOQUOTES` flag skips encoding of single and double quotes. If the resulting string is embedded inside HTML attributes, attackers can break out of the target attribute context and inject malicious scripts. Prefer using `ENT_QUOTES` or robust contextual output encoding.
greprules fetch cve-2026-30919-php-insecure-htmlspecialchars-noquotes --engine opengrepDescription
Using `htmlspecialchars()` with the `ENT_NOQUOTES` flag skips encoding of single and double quotes. If the resulting string is embedded inside HTML attributes, attackers can break out of the target attribute context and inject malicious scripts. Prefer using `ENT_QUOTES` or robust contextual output encoding.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.