Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
dompurify DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS Low Risk 3.0 2 hours ago 2 hours ago
dompurify DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS Medium Risk 6.0 1 month ago 20 days ago
dompurify DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low Risk 3.0 2 months ago 20 days ago
dompurify DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM Medium Risk 6.1 3 months ago 20 days ago
dompurify DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) Medium Risk 6.0 3 months ago 20 days ago
dompurify DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback Medium Risk 6.9 5 months ago 20 days ago
dompurify DOMPurify is vulnerable to mutation-XSS via Re-Contextualization Medium Risk 6.0 6 months ago 20 days ago
dompurify DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects Low Risk 3.0 3 months ago 20 days ago
dompurify DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content Medium Risk 6.0 3 months ago 20 days ago
dompurify DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes Low Risk 3.0 3 months ago 20 days ago
dompurify DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks Medium Risk 6.1 3 months ago 20 days ago
dompurify DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` Medium Risk 6.1 3 months ago 20 days ago
dompurify DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix) Medium Risk 6.0 5 months ago 20 days ago
dompurify DOMPurify USE_PROFILES prototype pollution allows event handlers Medium Risk 6.0 6 months ago 20 days ago
dompurify DOMPurify ADD_ATTR predicate skips URI validation Medium Risk 6.0 6 months ago 20 days ago
dompurify DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode Medium Risk 6.8 5 months ago 20 days ago
dompurify DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation Medium Risk 6.0 5 months ago 20 days ago
dompurify DOMPurify contains a Cross-site Scripting vulnerability Medium Risk 6.1 7 months ago 20 days ago
dompurify DOMPurify contains a Cross-site Scripting vulnerability Medium Risk 6.1 7 months ago 20 days ago
dompurify DOMpurify has a nesting-based mXSS Critical 10.0 1 year ago 20 days ago
dompurify DOMPurify allows tampering by prototype pollution High Risk 7.0 2 years ago 20 days ago
dompurify DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output Low Risk 3.0 3 months ago 20 days ago
dompurify DOMPurify allows Cross-site Scripting (XSS) Medium Risk 4.5 1 year ago 20 days ago
dompurify DOMPurify XSS via selectedcontent re-clone High Risk 8.2 4 months ago 4 months ago
dompurify DOMPurify vulnerable to tampering by prototype polution Critical 9.1 1 year ago 11 months ago
express-dompurify Malicious code in express-dompurify (npm) Unknown 1 year ago 1 year ago
dompurify DOMPurify Open Redirect vulnerability Medium Risk 6.1 2 years ago 2 years ago
dompurify Cross-site Scripting in dompurify Medium Risk 6.1 5 years ago 2 years ago
dompurify Cross-Site Scripting in dompurify Medium Risk 6.1 6 years ago 2 years ago
dompurify dompurify vulnerable to Cross-site Scripting Medium Risk 6.0 3 years ago 3 years ago
dompurify dompurify vulnerable to Cross-site Scripting Medium Risk 6.0 3 years ago 3 years ago
dompurify Cross-Site Scripting in dompurify Critical 9.5 6 years ago 5 years ago