CVE Tools

Xmldom

15 CVEs tracked since 2026. Since Sep 2026, none of them reached CISA KEV.

Xmldom CVEs per month

Sep 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Xmldom CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-09150

Products

The products that kept showing up in Xmldom's monthly top three, with their CVEs summed over those months.

  1. Xmldom151 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Xmldom.

  1. CVE-2026-83619xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser—
  2. CVE-2026-83618xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator—
  3. CVE-2026-83617xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator—
  4. CVE-2026-83616xmldom: Processing Instruction Target Injection Bypasses requireWellFormed—
  5. CVE-2026-83615xmldom: Quadratic-memory consumption—
  6. CVE-2026-83614xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge—
  7. CVE-2026-83613xmldom: Quadratic-time attribute deduplication—
  8. CVE-2026-83612xmldom: HTML raw-text closing-tag case mismatch causes output amplification—
  9. CVE-2026-83611xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content—
  10. CVE-2026-83610xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization—
  11. CVE-2026-83609xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path—
  12. CVE-2026-83608xmldom: DocType `name` Injection Bypasses requireWellFormed—
  13. CVE-2026-83607xmldom: Element name injection via createElement() bypasses requireWellFormed—
  14. CVE-2026-83606xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions—
  15. CVE-2026-83605xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed—

The record

Peak rank
#80 in Sep 2026
Busiest month shown
Sep 2026, 15 CVEs
Months with a KEV entry
0 since Sep 2026
Monthly snapshots
1 since 2026
Xmldom's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store