DOMPurify
Cure53 · 27 CVEs
DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook
Aug 18, 2026
DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING
Jul 24, 2026
DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
Jul 23, 2026
DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
Jul 23, 2026
DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR
Jul 23, 2026
DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage
Jul 23, 2026
DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode
Jul 23, 2026
DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
Jul 23, 2026
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
Jul 23, 2026
DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName
Jul 23, 2026
DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM
Jul 23, 2026
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
Jul 23, 2026
DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig
Jul 23, 2026
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
Jul 14, 2026
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
Jul 14, 2026
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
Jul 14, 2026
DOMPurify XSS via `selectedcontent` re-clone
Jul 14, 2026
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
Apr 23, 2026
DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
Apr 23, 2026
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
Apr 23, 2026
DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML
Mar 3, 2026
DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML
Mar 3, 2026
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the curre…
May 15, 2025
dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling
Feb 14, 2025
DOMPurify vulnerable to tampering by prototype polution
Oct 31, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-75838 | DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook | MEDIUM | 0.30% | Aug 18, 2026 |
| CVE-2026-66010 | DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING | MEDIUM | 0.30% | Jul 24, 2026 |
| CVE-2026-65914 | DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization | MEDIUM | 0.31% | Jul 23, 2026 |
| CVE-2026-65913 | DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES | MEDIUM | 0.32% | Jul 23, 2026 |
| CVE-2026-65912 | DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR | MEDIUM | 0.30% | Jul 23, 2026 |
| CVE-2026-65911 | DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage | MEDIUM | 0.33% | Jul 23, 2026 |
| CVE-2026-65904 | DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode | LOW | 0.27% | Jul 23, 2026 |
| CVE-2026-65903 | DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS | MEDIUM | 0.33% | Jul 23, 2026 |
| CVE-2026-65902 | DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags | MEDIUM | 0.36% | Jul 23, 2026 |
| CVE-2026-65901 | DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName | MEDIUM | 0.29% | Jul 23, 2026 |
| CVE-2026-65900 | DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM | MEDIUM | 0.31% | Jul 23, 2026 |
| CVE-2026-65899 | DOMPurify before 3.4.9 Trusted Types Policy State Contamination | MEDIUM | 0.41% | Jul 23, 2026 |
| CVE-2026-65898 | DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig | MEDIUM | 0.30% | Jul 23, 2026 |
| CVE-2026-49978 | DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content | MEDIUM | 0.40% | Jul 14, 2026 |
| CVE-2026-49459 | DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM | MEDIUM | 0.36% | Jul 14, 2026 |
| CVE-2026-49458 | DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks | MEDIUM | 0.40% | Jul 14, 2026 |
| CVE-2026-47423 | DOMPurify XSS via `selectedcontent` re-clone | HIGH | 0.41% | Jul 14, 2026 |
| CVE-2026-41240 | DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix) | MEDIUM | 0.40% | Apr 23, 2026 |
| CVE-2026-41239 | DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode | MEDIUM | 0.41% | Apr 23, 2026 |
| CVE-2026-41238 | DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback | MEDIUM | 0.35% | Apr 23, 2026 |
| CVE-2026-0540 | DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML | MEDIUM | 0.35% | Mar 3, 2026 |
| CVE-2025-15599 | DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML | MEDIUM | 0.25% | Mar 3, 2026 |
| CVE-2025-48050 | In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier… | HIGH | 0.47% | May 15, 2025 |
| CVE-2025-26791 | dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling | MEDIUM | 0.60% | Feb 14, 2025 |
| CVE-2024-48910 | DOMPurify vulnerable to tampering by prototype polution | CRITICAL | 1.15% | Oct 31, 2024 |
Showing 1 to 25 of 27 CVEs