Cure53 Dompurify vulnerabilities
29 known vulnerabilities affecting cure53/dompurify.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM25
Vulnerabilities
Page 2 of 2
CVE-2025-15599P4MEDIUMCVSS 6.1≥ 2.5.3, ≤ 2.5.8≥ 3.1.3, < 3.2.7+1 more2026-03-03
CVE-2025-15599 [MEDIUM] CWE-79 CVE-2025-15599: DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability t
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute
ghsanvdosv
CVE-2024-45801P4MEDIUMCVSS 6.1fixed in 2.5.4≥ 3.0.0, < 3.1.3+1 more2024-09-16
CVE-2024-45801 [MEDIUM] CWE-1333 CVE-2024-45801: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has be
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid
ghsanvdosv
CVE-2019-25155P4MEDIUMCVSS 6.1fixed in 1.0.112023-11-07
CVE-2019-25155 [MEDIUM] CWE-601 CVE-2019-25155: DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because link
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
ghsanvdosv
CVE-2026-65911P4MEDIUMCVSS 6.1fixed in 3.4.02026-07-23
CVE-2026-65911 [MEDIUM] CWE-79 CVE-2026-65911: In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanit
In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call on the same instance provides ADD_ATTR or ADD_TAGS as an array rather than a function, the previously set function handler
nvd
CVE-2026-65901P4MEDIUMCVSS 6.1≤ 3.4.62026-07-23
CVE-2026-65901 [MEDIUM] CWE-79 CVE-2026-65901: DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts a
DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inse
nvd
CVE-2019-16728P4MEDIUMCVSS 6.1fixed in 2.0.12019-09-24
CVE-2019-16728 [MEDIUM] CWE-79 CVE-2019-16728: DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a M
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
ghsanvdosv
CVE-2024-47875P4MEDIUMCVSS 6.1fixed in 2.5.0≥ 3.0.0, < 3.1.3+1 more2024-10-11
CVE-2024-47875 [MEDIUM] CWE-79 CVE-2024-47875: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
ghsanvdosv
CVE-2025-26791P4MEDIUMCVSS 6.1fixed in 3.2.42025-02-14
CVE-2025-26791 [MEDIUM] CWE-79 CVE-2025-26791: DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mu
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
ghsanvdosv
CVE-2026-65904P4MEDIUMCVSS 4.7≤ 3.3.32026-07-23
CVE-2026-65904 [MEDIUM] CWE-754 CVE-2026-65904: DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element ori
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to stringify the element (yielding '[object HTMLDivEle
nvd
← Previous2 / 2