DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
수정: 2026. 4. 16.
package
pkg:npm/dompurify
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
수정: 2026. 4. 16.
Cross-site Scripting in dompurify
수정: 2023. 11. 8.
DOMPurify Open Redirect vulnerability
수정: 2023. 11. 15.
Cross-Site Scripting in dompurify
수정: 2023. 11. 8.
DOMPurify USE_PROFILES prototype pollution allows event handlers
수정: 2026. 5. 29.
DOMPurify ADD_ATTR predicate skips URI validation
수정: 2026. 5. 29.
DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
수정: 2026. 5. 5.
DOMpurify has a nesting-based mXSS
수정: 2026. 2. 4.
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
수정: 2026. 5. 5.
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
수정: 2026. 4. 7.
Cross-Site Scripting in dompurify
수정: 2021. 9. 29.
DOMPurify allows tampering by prototype pollution
수정: 2026. 2. 4.
DOMPurify vulnerable to tampering by prototype polution
수정: 2025. 11. 3.
DOMPurify contains a Cross-site Scripting vulnerability
수정: 2026. 3. 30.
DOMPurify contains a Cross-site Scripting vulnerability
수정: 2026. 3. 10.
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
수정: 2026. 5. 5.
DOMPurify allows Cross-site Scripting (XSS)
수정: 2026. 2. 4.