Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dompurify MEDIUM 6.1
CVE-2026-66010

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing at…

Fix: 3.4.12+
Fix from $1,600 2026-07-24
Dompurify MEDIUM 6.1
CVE-2026-65914

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wra…

Fix: 3.3.2+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65911

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HA…

Fix: 3.4.0+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65912

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.at…

Fix: 3.3.2+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65913

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by pollu…

Fix: 3.3.2+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65901

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form node…

Fix: 3.4.7+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65902

DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets t…

Fix: 3.4.7+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65903

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS res…

Fix: 3.4.0+
Fix from $1,600 2026-07-23
Dompurify HIGH 7.2
CVE-2026-65898

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to p…

Fix: 3.4.11+
Fix from $1,950 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65899

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across tru…

Fix: 3.4.9+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65900

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT…

Fix: 3.4.8+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-49978

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow c…

Fix: 3.4.7+
Fix from $1,600 2026-07-14
Dompurify MEDIUM 6.1
CVE-2026-49458

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accept…

Fix: 3.4.6+
Fix from $1,600 2026-07-14
Dompurify MEDIUM 6.1
CVE-2026-49459

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could …

Fix: 3.4.6+
Fix from $1,600 2026-07-14
Dompurify HIGH 8.2
CVE-2026-47423

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing br…

Patch available
Fix from $1,950 2026-07-14
Dompurify MEDIUM 6.1
CVE-2026-41240

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS a…

Fix: 3.4.0+
Fix from $1,600 2026-04-23
Dompurify MEDIUM 6.1
CVE-2026-0540

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to…

Fix: after 3.3.1
Fix from $1,600 2026-03-03
Dompurify MEDIUM 6.1
CVE-2025-15599

DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitiza…

Fix: 3.2.7+
Fix from $1,600 2026-03-03
Dompurify MEDIUM 6.1
CVE-2025-26791

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

Fix: 3.2.4+
Fix from $1,600 2025-02-14
Dompurify CRITICAL 9.8
CVE-2024-48910

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vuln…

Fix: 2.4.2+
Fix from $2,300 2024-10-31
Dompurify MEDIUM 6.1
CVE-2024-47875

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulne…

Fix: 2.5.0 / 3.1.3+
Fix from $1,600 2024-10-11
Dompurify MEDIUM 6.1
CVE-2024-45801

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special n…

Fix: 2.5.4 / 3.1.3+
Fix from $1,600 2024-09-16
Dompurify MEDIUM 6.1
CVE-2019-25155

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

Fix: 1.0.11+
Fix from $1,600 2023-11-07