VDB
KO

package

npm / dompurify

pkg:npm/dompurify

MEDIUM npm
GHSA-39q2-94rc-95cp

DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation

Modified: 4/16/2026

MEDIUM npm
GHSA-cj63-jhhr-wcxv

DOMPurify USE_PROFILES prototype pollution allows event handlers

Modified: 5/29/2026

MEDIUM npm
GHSA-h8r8-wccr-v5f2

DOMPurify is vulnerable to mutation-XSS via Re-Contextualization

Modified: 4/7/2026