VulnSea

DOMPurify vulnerabilities

CVEs whose affected-version data names the DOMPurify package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

GHSA-55q2-fjhq-7xh7Medium
1mo ago

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

Sunlitdompurify · dompurifyvia GHSA
CVE-2026-66010Medium· 6.1PoC
2mo ago

DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attri…

Twilightcure53 · DOMPurifyEPSS 0.21%via CVEORG
GHSA-c2j3-45gr-mqc4Low
2mo ago

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

Sunlitdompurify · dompurifyvia GHSA
GHSA-cmwh-pvxp-8882Medium
3mo ago

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

Sunlitdompurify · dompurifyvia GHSA
CVE-2026-49459Medium· 6.1
3mo ago

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

Sunlitdompurify · dompurifyEPSS 0.36%via GHSA
CVE-2026-49458Medium· 6.1
3mo ago

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

Sunlitdompurify · dompurifyEPSS 0.40%via GHSA
GHSA-76mc-f452-cxcmMedium· 6.1
3mo ago

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

Sunlitdompurify · dompurifyvia GHSA
GHSA-x4vx-rjvf-j5p4Low
3mo ago

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

Sunlitdompurify · dompurifyvia GHSA
GHSA-gvmj-g25r-r7wrLow
3mo ago

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

Sunlitdompurify · dompurifyvia GHSA
GHSA-vxr8-fq34-vvx9Low
3mo ago

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

Sunlitdompurify · dompurifyvia GHSA
DOMPurify vulnerabilities (CVEs) · VulnSea