HIGH🇵🇱 Wersja polska

CVE-2026-47423

CVSS 8.2v3.1pub. 2026-07-14upd. 2026-07-21

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
  • Cure53 Dompurify

    APP
    Cure53
    3.4.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2024-48910CRITICAL9.1PL ✓same product

Prototype pollution w bibliotece DOMPurify umożliwiający XSS

CVE-2024-47875CRITICAL10.0PL ✓same product

DOMPurify — podatność mXSS oparta na zagnieżdżaniu znaczników

CVE-2024-45801HIGH7.3same product

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discove...

CVE-2026-66010MEDIUM5.1same product

DOMPurify przed wersją 3.4.12 nie wykonuje hook'a afterSanitizeElements dla custom elements dozwolonych przez ...

CVE-2026-65898MEDIUM5.1same product

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitiz...