CVE-2024-47875
published 2024-10-11CVE-2024-47875: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability…
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.07%
61.3th percentile
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | >= 0 < 1.2.16+ds1-2+deb11u5 | 1.2.16+ds1-2+deb11u5 |
| cacti | cacti | >= 0 < 1.2.24+ds1-1+deb12u2 | 1.2.24+ds1-1+deb12u2 |
| cacti | cacti | >= 0 < 1.2.26+ds1-1 | 1.2.26+ds1-1 |
| cacti | cacti | >= 0 < 1.2.26+ds1-1 | 1.2.26+ds1-1 |
| cure53 | dompurify | < 3.1.3 | 3.1.3 |
| cure53 | dompurify | < 2.5.0 | 2.5.0 |
| cure53 | dompurify | >= 0 < 2.5.0 | 2.5.0 |
| cure53 | dompurify | >= 3.0.0 < 3.1.3 | 3.1.3 |
| cure53 | dompurify | >= 3.0.0 < 3.1.3 | 3.1.3 |
| debian | cacti | < cacti 1.2.24+ds1-1+deb12u2 (bookworm) | cacti 1.2.24+ds1-1+deb12u2 (bookworm) |
| debian | node-dompurify | < cacti 1.2.24+ds1-1+deb12u2 (bookworm) | cacti 1.2.24+ds1-1+deb12u2 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS
cisa_ics·2026-02-12·CVSS 3.4
[LOW] Siemens COMOS
ICS Advisory
##
Siemens COMOS
Release DateFebruary 12, 2026
Alert CodeICSA-26-043-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
COMOS is affected by multiple vulnerabilities that could allow an attacker to execute arbitrary code or cause denial of service condition, data infiltration or perform access control violations. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens COMOS are affected:
- COMOS V10.4 vers:intdot/<10.4.5, vers:intdot/<10.4.5 (CVE-2024-47875, CVE-2025-278
Red Hat
dompurify: nesting-based mutation XSS vulnerability
vendor_redhat·2024-10-11·CVSS 10.0
CVE-2024-47875 [CRITICAL] CWE-79 dompurify: nesting-based mutation XSS vulnerability
dompurify: nesting-based mutation XSS vulnerability
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
A flaw was found in DOMPurify that could allow for a nesting-based mXSS to not be properly sanitized.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: migration-toolkit-virtualization/mtv-console-plugin-rhel9 (Migration Toolkit for Virtualization) - Not affected
Package: multicluster-engine/console-mce-rhel8 (Multicluster Engine for Kubernetes) - N
Debian
CVE-2024-47875: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...
vendor_debian·2024·CVSS 10.0
CVE-2024-47875 [CRITICAL] CVE-2024-47875: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u2)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5)
forky: resolved (fixed in 1.2.26+ds1-1)
sid: resolved (fixed in 1.2.26+ds1-1)
trixie: resolved (fixed in 1.2.26+ds1-1)
GHSA
DOMpurify has a nesting-based mXSS
ghsa·2024-10-11·CVSS 6.1
CVE-2024-47875 [MEDIUM] CWE-79 DOMpurify has a nesting-based mXSS
DOMpurify has a nesting-based mXSS
DOMpurify was vulnerable to nesting-based mXSS
fixed by [0ef5e537](https://github.com/cure53/DOMPurify/tree/0ef5e537a514f904b6aa1d7ad9e749e365d7185f) (2.x) and
[merge 943](https://github.com/cure53/DOMPurify/pull/943)
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under [test](https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098)
OSV
CVE-2024-47875: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG
osv·2024-10-11·CVSS 6.1
CVE-2024-47875 [MEDIUM] CVE-2024-47875: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
OSV
DOMpurify has a nesting-based mXSS
osv·2024-10-11·CVSS 6.1
CVE-2024-47875 [MEDIUM] DOMpurify has a nesting-based mXSS
DOMpurify has a nesting-based mXSS
DOMpurify was vulnerable to nesting-based mXSS
fixed by [0ef5e537](https://github.com/cure53/DOMPurify/tree/0ef5e537a514f904b6aa1d7ad9e749e365d7185f) (2.x) and
[merge 943](https://github.com/cure53/DOMPurify/pull/943)
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under [test](https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098https://github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185fhttps://github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7ahttps://github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jfhttp://seclists.org/fulldisclosure/2025/Apr/14https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html
2024-10-11
Published