VendorsCure53dompurifyany version
Vulnerabilities

Cure53 DOMPurify any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2024-47875
DOMPurify nesting-based mXSS
Published 2024-10-11 · Modified
10.0EPSS 0.011
CVE-2024-48910
DOMPurify vulnerable to tampering by prototype polution
Published 2024-10-31 · Modified
9.8EPSS 0.012
CVE-2024-45801
Tampering by prototype polution in DOMPurify
Published 2024-09-16 · Analyzed
7.3EPSS 0.009
CVE-2026-65898
DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig
Published 2026-07-23 · Analyzed
7.2EPSS 0.003
CVE-2026-49978
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
Published 2026-07-14 · Analyzed
6.3EPSS 0.004
CVE-2020-26870
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Published 2020-10-07 · Modified
6.1EPSS 0.049
CVE-2019-16728
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
Published 2019-09-24 · Modified
6.1EPSS 0.017
CVE-2025-26791
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Published 2025-02-14 · Analyzed
6.1EPSS 0.006
CVE-2019-25155
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Published 2023-10-31 · Modified
6.1EPSS 0.005
CVE-2026-65899
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
Published 2026-07-23 · Analyzed
6.1EPSS 0.004
CVE-2026-41240
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
Published 2026-04-23 · Analyzed
6.1EPSS 0.004
CVE-2026-49458
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
Published 2026-07-14 · Analyzed
6.1EPSS 0.004
CVE-2026-49459
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
Published 2026-07-14 · Analyzed
6.1EPSS 0.004
CVE-2026-65902
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
Published 2026-07-23 · Analyzed
6.1EPSS 0.004
CVE-2026-0540
DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML
Published 2026-03-03 · Modified
6.1EPSS 0.003
CVE-2026-65911
DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2026-65903
DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2026-65913
DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2026-65900
DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2026-65914
DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2026-66010
DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING
Published 2026-07-24 · Analyzed
6.1EPSS 0.003
CVE-2026-65912
DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2026-65901
DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2025-15599
DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML
Published 2026-03-03 · Analyzed
6.1EPSS 0.002
CVE-2026-65904
DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode
Published 2026-07-23 · Analyzed
4.7EPSS 0.003