DOMPurify
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 16, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode
DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage
DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM
DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
Monitor DOMPurify in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.