18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether xmldom is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-83610

xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization

HIGH 7.5
npm

CVE-2026-34601

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

UNKNOWN
npm

CVE-2026-41672

xmldom has XML node injection through unvalidated comment serialization

UNKNOWN
npm

CVE-2026-41675

xmldom has XML node injection through unvalidated processing instruction serialization

UNKNOWN
npm

CVE-2026-41674

xmldom has XML injection through unvalidated DocumentType serialization

UNKNOWN
npm

CVE-2026-41673

xmldom: Uncontrolled recursion in XML serialization leads to DoS

CRITICAL 9.8
npm

CVE-2022-39353

xmldom allows multiple root nodes in a DOM

MEDIUM 6.5
npm

CVE-2021-32796

Misinterpretation of malicious XML input

MEDIUM 4.3
npm

CVE-2021-21366

Misinterpretation of malicious XML input

UNKNOWN
npm

CVE-2026-83613

xmldom: Quadratic-time attribute deduplication

UNKNOWN
npm

CVE-2026-83616

xmldom: Processing Instruction Target Injection Bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83615

xmldom: Quadratic-memory consumption

UNKNOWN
npm

CVE-2026-83614

xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge

UNKNOWN
npm

CVE-2026-83611

xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content

UNKNOWN
npm

CVE-2026-83608

xmldom: DocType `name` Injection Bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83607

xmldom: Element name injection via createElement() bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83605

xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

CRITICAL 9.8
npm

CVE-2022-37616

Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes