VendorsXmldom Projectxmldomall versions
Vulnerabilities

Xmldom Project Xmldom 0.5.0 for Node.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-37616
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
Published 2022-10-11 · Modified
9.8EPSS 0.017
CVE-2022-39353
xmldom allows multiple root nodes in a DOM
Published 2022-11-02 · Modified
9.8EPSS 0.013
CVE-2021-32796
Misinterpretation of malicious XML input in xmldom
Published 2021-07-27 · Modified
6.5EPSS 0.014
CVE-2021-21366
Misinterpretation of malicious XML input
Published 2021-03-12 · Modified
4.3EPSS 0.013