cure53
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 24, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
DOMPurify XSS via `selectedcontent` re-clone
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML
DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML
DOMPurify vulnerable to tampering by prototype polution
DOMPurify nesting-based mXSS
Monitor cure53 in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.