18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether xmldom is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-83610
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
HIGH 7.5
CVE-2026-34601
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
UNKNOWN
CVE-2026-41672
xmldom has XML node injection through unvalidated comment serialization
UNKNOWN
CVE-2026-41675
xmldom has XML node injection through unvalidated processing instruction serialization
UNKNOWN
CVE-2026-41674
xmldom has XML injection through unvalidated DocumentType serialization
UNKNOWN
CVE-2026-41673
xmldom: Uncontrolled recursion in XML serialization leads to DoS
CRITICAL 9.8
CVE-2022-39353
xmldom allows multiple root nodes in a DOM
MEDIUM 6.5
CVE-2021-32796
Misinterpretation of malicious XML input
MEDIUM 4.3
CVE-2021-21366
Misinterpretation of malicious XML input
UNKNOWN
CVE-2026-83613
xmldom: Quadratic-time attribute deduplication
UNKNOWN
CVE-2026-83616
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
UNKNOWN
CVE-2026-83615
xmldom: Quadratic-memory consumption
UNKNOWN
CVE-2026-83614
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
UNKNOWN
CVE-2026-83611
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
UNKNOWN
CVE-2026-83608
xmldom: DocType `name` Injection Bypasses requireWellFormed
UNKNOWN
CVE-2026-83607
xmldom: Element name injection via createElement() bypasses requireWellFormed
UNKNOWN
CVE-2026-83605
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
CRITICAL 9.8
CVE-2022-37616
Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes