28 Total advisories
28 Vulnerabilities
0 Malware

Dependency scanning

Check whether dompurify is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-75838

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

UNKNOWN
npm

CVE-2026-66010

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

MEDIUM 6.1
npm

CVE-2026-49459

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

UNKNOWN
npm

CVE-2026-65898

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

MEDIUM 6.9
npm

CVE-2026-41238

DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback

UNKNOWN
npm

CVE-2026-65914

DOMPurify is vulnerable to mutation-XSS via Re-Contextualization

UNKNOWN
npm

CVE-2026-65901

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

UNKNOWN
npm

CVE-2026-49978

DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content

MEDIUM 6.1
npm

CVE-2026-49458

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

UNKNOWN
npm

CVE-2026-65900

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

MEDIUM 6.1
npm

CVE-2026-65902

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

UNKNOWN
npm

CVE-2026-41240

DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)

MEDIUM 6.8
npm

CVE-2026-41239

DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode

UNKNOWN
npm

CVE-2026-65912

DOMPurify ADD_ATTR predicate skips URI validation

UNKNOWN
npm

CVE-2026-65913

DOMPurify USE_PROFILES prototype pollution allows event handlers

UNKNOWN
npm

CVE-2026-65903

DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation

MEDIUM 6.1
npm

CVE-2025-15599

DOMPurify contains a Cross-site Scripting vulnerability

MEDIUM 6.1
npm

CVE-2026-0540

DOMPurify contains a Cross-site Scripting vulnerability

CRITICAL 10.0
npm

CVE-2024-47875

DOMpurify has a nesting-based mXSS

HIGH 7.0
npm

CVE-2024-45801

DOMPurify allows tampering by prototype pollution

UNKNOWN
npm

CVE-2026-65899

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

MEDIUM 4.5
npm

CVE-2025-26791

DOMPurify allows Cross-site Scripting (XSS)

HIGH 8.2
npm

CVE-2026-47423

DOMPurify XSS via selectedcontent re-clone

CRITICAL 9.1
npm

CVE-2024-48910

DOMPurify vulnerable to tampering by prototype polution

MEDIUM 6.1
npm

CVE-2019-25155

DOMPurify Open Redirect vulnerability

MEDIUM 6.1
npm

CVE-2020-26870

Cross-site Scripting in dompurify

MEDIUM 6.1
npm

CVE-2019-16728

Cross-Site Scripting in dompurify

UNKNOWN
npm

GHSA-mjjq-c88q-qhr6

Cross-Site Scripting in dompurify

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes