Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fast Xml Parser MEDIUM 6.1
CVE-2026-41650

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not es…

Fix: 5.7.0+
Fix from $1,600 2026-05-07
Fast Xml Parser MEDIUM 5.9
CVE-2026-33349

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.…

Fix: 4.5.5 / 5.5.7+
Fix from $1,600 2026-03-24
Fast Xml Parser HIGH 7.5
CVE-2026-33036

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a …

Fix: 5.5.6+
Fix from $1,950 2026-03-20
Fast Xml Parser HIGH 7.5
CVE-2026-27942

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prio…

Fix: 4.5.4 / 5.3.8+
Fix from $1,950 2026-02-26
Fast Xml Parser CRITICAL 9.3
CVE-2026-25896

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From…

Fix: 5.3.5+
Fix from $2,300 2026-02-20
Fast Xml Parser HIGH 7.5
CVE-2026-26278

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In v…

Fix: 5.3.6+
Fix from $1,950 2026-02-19
Fast Xml Parser HIGH 7.5
CVE-2026-25128

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In v…

Fix: 5.3.4+
Fix from $1,950 2026-01-30
Fast Xml Parser HIGH 7.5
CVE-2024-41818

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.

Patch available
Fix from $1,950 2024-07-29
Fast Xml Parser MEDIUM 6.5
CVE-2023-26920

fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.

Fix: 4.1.2+
Fix from $1,600 2023-12-12
Fast Xml Parser HIGH 7.5
CVE-2023-34104

fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sa…

Fix: 4.2.4+
Fix from $1,950 2023-06-06