CVE-2026-75838
- EPSS 0.3%
- Veröffentlicht 18.08.2026 11:19:47
- Zuletzt bearbeitet 24.09.2026 20:02:50
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after s...
CVE-2026-66010
- EPSS 0.17%
- Veröffentlicht 24.07.2026 12:07:57
- Zuletzt bearbeitet 06.08.2026 00:47:37
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on cust...
CVE-2026-65914
- EPSS 0.17%
- Veröffentlicht 23.07.2026 13:16:24
- Zuletzt bearbeitet 28.07.2026 15:49:47
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with clo...
CVE-2026-65913
- EPSS 0.19%
- Veröffentlicht 23.07.2026 13:16:24
- Zuletzt bearbeitet 28.07.2026 15:50:09
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, c...
CVE-2026-65912
- EPSS 0.18%
- Veröffentlicht 23.07.2026 13:16:23
- Zuletzt bearbeitet 28.07.2026 15:50:27
DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute and tag combinations t...
CVE-2026-65911
- EPSS 0.19%
- Veröffentlicht 23.07.2026 13:16:22
- Zuletzt bearbeitet 28.07.2026 15:50:57
In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call on the same instance...
CVE-2026-65904
- EPSS 0.17%
- Veröffentlicht 23.07.2026 13:16:22
- Zuletzt bearbeitet 28.07.2026 15:51:19
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns fa...
CVE-2026-65903
- EPSS 0.2%
- Veröffentlicht 23.07.2026 13:16:21
- Zuletzt bearbeitet 28.07.2026 15:51:38
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via AD...
CVE-2026-65902
- EPSS 0.21%
- Veröffentlicht 23.07.2026 13:16:20
- Zuletzt bearbeitet 28.07.2026 15:51:48
DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data.allowedAttribut...
CVE-2026-65901
- EPSS 0.17%
- Veröffentlicht 23.07.2026 13:16:19
- Zuletzt bearbeitet 28.07.2026 15:52:12
DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName ...