Dompurify
44 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Dompurify, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Dompurify CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 1 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 6 |
| 2026-05 | 0 |
| 2026-06 | 5 |
| 2026-07 | 17 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 44 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High4
- Medium23
Latest CVEs
The 15 most recently published vulnerabilities affecting Dompurify.
- CVE-2026-75838DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook—
- GHSA-55q2-fjhq-7xh7DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS—
- CVE-2026-66010DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING6.1
- CVE-2026-65913DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES6.1
- CVE-2026-65914DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization6.1
- CVE-2026-65912DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR6.1
- CVE-2026-65911DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage6.1
- CVE-2026-65904DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode4.7
- CVE-2026-65903DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS6.1
- CVE-2026-65902DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags6.1
- CVE-2026-65901DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName6.1
- CVE-2026-65900DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM6.1
- CVE-2026-65899DOMPurify before 3.4.9 Trusted Types Policy State Contamination6.1
- CVE-2026-65898DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig7.2
- GHSA-c2j3-45gr-mqc4DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.—
Product grouping is registry-driven, with AI assist and human review. How it works