📦 Dompurify

by Cure53

🔍 What is Dompurify?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-47875

CRITICAL CVSS 10.0 Oct 11, 2024

DOMPurify versions before 2.5.0 and 3.1.3 contain a nesting-based mutation XSS (mXSS) vulnerability that allows attackers to bypass HTML sanitization and execute arbitrary JavaScript in victim browser...

CVE-2026-0540

MEDIUM CVSS 6.1 Mar 3, 2026

This CVE describes a cross-site scripting (XSS) vulnerability in DOMPurify that allows attackers to bypass HTML sanitization when output is placed in XML contexts. Attackers can inject malicious JavaS...

CVE-2025-15599

MEDIUM CVSS 6.1 Mar 3, 2026

This CVE describes a cross-site scripting vulnerability in DOMPurify that allows attackers to bypass HTML sanitization by injecting malicious closing tags like </textarea> into attribute values. When ...

CVE-2025-26791

MEDIUM CVSS 4.5 Feb 14, 2025

DOMPurify versions before 3.2.4 contain a regular expression flaw in template literal handling that can allow mutation cross-site scripting (mXSS) attacks. This vulnerability enables attackers to bypa...