What can I use to sanitize received HTML while retaining basic formatting?

This is an older, but still relevant question.

We are using the HtmlSanitizer .Net library, which:

  • is open-source
  • is actively maintained
  • doesn’t have the problems like Microsoft Anti-XSS library,
  • Is unit tested with the
    OWASP XSS Filter Evasion Cheat Sheet
  • is special built for this (in contrast to HTML Agility Pack, which is a parser)

Also on NuGet

Leave a Comment

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)