cure53 DOMPurify
20 known vulnerabilities in cure53 DOMPurify, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-75838 CVSS 5.1 medium DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to…
- CVE-2026-66010 CVSS 5.1 medium DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck…
- CVE-2026-65914 CVSS 5.3 medium DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using…
- CVE-2026-65913 CVSS 5.1 medium DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute…
- CVE-2026-65912 CVSS 5.1 medium DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via…
- CVE-2026-65911 CVSS 5.1 medium In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state…
- CVE-2026-65904 CVSS 2.3 low DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm…
- CVE-2026-65903 CVSS 5.1 medium DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass…
- CVE-2026-65902 CVSS 5.3 medium DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and…
- CVE-2026-65901 CVSS 5.1 medium DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live…
- CVE-2026-65900 CVSS 5.1 medium DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM…
- CVE-2026-65899 CVSS 5.1 medium DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused…
- CVE-2026-65898 CVSS 5.1 medium DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing…
- CVE-2026-49978 CVSS 6.3 medium DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could…
- CVE-2026-49459 CVSS 6.1 medium DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE…
- CVE-2026-49458 CVSS 6.1 medium DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE…
- CVE-2026-41240 CVSS 6.0 medium DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between…
- CVE-2026-41239 CVSS 6.8 medium DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0…
- CVE-2026-41238 CVSS 6.9 medium DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a…
- CVE-2026-0540 CVSS 5.3 medium DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows…