DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
Modified: 9/10/2026
package
pkg:npm/dompurify
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
Modified: 9/10/2026
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
Modified: 9/10/2026
Cross-site Scripting in dompurify
Modified: 11/8/2023
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
Modified: 9/10/2026
DOMPurify XSS via selectedcontent re-clone
Modified: 6/1/2026
DOMPurify Open Redirect vulnerability
Modified: 11/15/2023
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Modified: 9/10/2026
Cross-Site Scripting in dompurify
Modified: 11/8/2023
DOMPurify USE_PROFILES prototype pollution allows event handlers
Modified: 9/10/2026
DOMPurify ADD_ATTR predicate skips URI validation
Modified: 9/10/2026
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
Modified: 9/10/2026
DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
Modified: 9/10/2026
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
Modified: 9/10/2026
DOMpurify has a nesting-based mXSS
Modified: 9/10/2026
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
Modified: 9/10/2026
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
Modified: 9/10/2026
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
Modified: 9/10/2026
Cross-Site Scripting in dompurify
Modified: 9/29/2021
DOMPurify allows tampering by prototype pollution
Modified: 9/10/2026
DOMPurify vulnerable to tampering by prototype polution
Modified: 11/3/2025
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
Modified: 9/10/2026
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
Modified: 9/10/2026
DOMPurify contains a Cross-site Scripting vulnerability
Modified: 9/10/2026
DOMPurify contains a Cross-site Scripting vulnerability
Modified: 9/10/2026
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
Modified: 9/10/2026
DOMPurify allows Cross-site Scripting (XSS)
Modified: 9/10/2026
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
Modified: 9/10/2026
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
Modified: 9/10/2026