VulnSea

dompurify has 9 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 7 in the 90 before. The busiest recent month was June 2026 with 7. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (7) and CWE-693 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
2 prev 7

Products

  • dompurify 9
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

dompurify vulnerabilities

CVEs affecting dompurify, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

GHSA-55q2-fjhq-7xh7Medium
1mo ago

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

Sunlitdompurify · dompurifyvia GHSA
GHSA-c2j3-45gr-mqc4Low
2mo ago

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

Sunlitdompurify · dompurifyvia GHSA
GHSA-cmwh-pvxp-8882Medium
3mo ago

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

Sunlitdompurify · dompurifyvia GHSA
CVE-2026-49459Medium· 6.1
3mo ago

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

Sunlitdompurify · dompurifyEPSS 0.36%via GHSA
CVE-2026-49458Medium· 6.1
3mo ago

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

Sunlitdompurify · dompurifyEPSS 0.40%via GHSA
GHSA-76mc-f452-cxcmMedium· 6.1
3mo ago

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

Sunlitdompurify · dompurifyvia GHSA
GHSA-x4vx-rjvf-j5p4Low
3mo ago

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

Sunlitdompurify · dompurifyvia GHSA
GHSA-gvmj-g25r-r7wrLow
3mo ago

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

Sunlitdompurify · dompurifyvia GHSA
GHSA-vxr8-fq34-vvx9Low
3mo ago

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

Sunlitdompurify · dompurifyvia GHSA
dompurify vulnerabilities (CVEs) · VulnSea