CVE-2026-65900
- EPSS 0.18%
- Veröffentlicht 23.07.2026 13:16:19
- Zuletzt bearbeitet 28.07.2026 15:52:37
DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <templat...
CVE-2026-65899
- EPSS 0.23%
- Veröffentlicht 23.07.2026 13:16:18
- Zuletzt bearbeitet 28.07.2026 15:53:23
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests...
CVE-2026-65898
- EPSS 0.17%
- Veröffentlicht 23.07.2026 13:16:17
- Zuletzt bearbeitet 28.07.2026 15:54:05
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dange...
CVE-2026-49978
- EPSS 0.33%
- Veröffentlicht 14.07.2026 20:02:46
- Zuletzt bearbeitet 21.07.2026 19:49:00
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as...
CVE-2026-49459
- EPSS 0.3%
- Veröffentlicht 14.07.2026 20:01:44
- Zuletzt bearbeitet 21.07.2026 19:51:07
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbe...
CVE-2026-49458
- EPSS 0.38%
- Veröffentlicht 14.07.2026 19:58:50
- Zuletzt bearbeitet 21.07.2026 19:47:48
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing...
CVE-2026-47423
- EPSS 0.27%
- Veröffentlicht 14.07.2026 19:56:02
- Zuletzt bearbeitet 21.07.2026 19:50:48
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedconte...
CVE-2026-41240
- EPSS 0.31%
- Veröffentlicht 23.04.2026 14:54:32
- Zuletzt bearbeitet 29.04.2026 14:58:30
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for ...
CVE-2026-41239
- EPSS 0.25%
- Veröffentlicht 23.04.2026 14:47:56
- Zuletzt bearbeitet 23.04.2026 16:18:41
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RE...
CVE-2026-41238
- EPSS 0.23%
- Veröffentlicht 23.04.2026 14:43:17
- Zuletzt bearbeitet 23.04.2026 18:16:29
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (n...