Cure53

Dompurify

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 18.08.2026 11:19:47
  • Zuletzt bearbeitet 24.09.2026 20:02:50

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after s...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 24.07.2026 12:07:57
  • Zuletzt bearbeitet 06.08.2026 00:47:37

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on cust...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 23.07.2026 13:16:24
  • Zuletzt bearbeitet 28.07.2026 15:49:47

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with clo...

  • EPSS 0.19%
  • Veröffentlicht 23.07.2026 13:16:24
  • Zuletzt bearbeitet 28.07.2026 15:50:09

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, c...

  • EPSS 0.18%
  • Veröffentlicht 23.07.2026 13:16:23
  • Zuletzt bearbeitet 28.07.2026 15:50:27

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute and tag combinations t...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 23.07.2026 13:16:22
  • Zuletzt bearbeitet 28.07.2026 15:50:57

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call on the same instance...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 23.07.2026 13:16:22
  • Zuletzt bearbeitet 28.07.2026 15:51:19

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns fa...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 23.07.2026 13:16:21
  • Zuletzt bearbeitet 28.07.2026 15:51:38

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via AD...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 23.07.2026 13:16:20
  • Zuletzt bearbeitet 28.07.2026 15:51:48

DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data.allowedAttribut...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 23.07.2026 13:16:19
  • Zuletzt bearbeitet 28.07.2026 15:52:12

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName ...