A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41673 @xmldom/xmldom is vulnerable to Uncontrolled Recursion in versions 0.0.0 - 0.8.13 and 0.9.0 - 0.9.10. | 0.0.0 - 0.8.130.9.0 - 0.9.10 | High |
CVE-2026-41674 @xmldom/xmldom is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 0.8.13 and 0.9.0 - 0.9.10. | 0.0.0 - 0.8.130.9.0 - 0.9.10 | High |
CVE-2026-41675 @xmldom/xmldom is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 0.8.13 and 0.9.0 - 0.9.10. | 0.0.0 - 0.8.130.9.0 - 0.9.10 | High |
CVE-2026-41672 @xmldom/xmldom is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 0.8.13 and 0.9.0 - 0.9.10. | 0.0.0 - 0.8.130.9.0 - 0.9.10 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant