DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It's written in JavaScript and works in all modern browsers (Safari, Opera (15+), Internet Explorer (10+), Firefox and Chrome - as well as almost anything else usin
85%
Total Score
100
100
100
75
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-47423 New dompurify is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.4.4 - 3.4.4. | 3.4.4 - 3.4.4 | High |
AIKIDO-2026-10955 dompurify is vulnerable to Protection Mechanism Failure in versions 0.0.1 - 3.4.5. | 0.0.1 - 3.4.5 | Medium |
AIKIDO-2026-10954 dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.4.5. | 0.0.1 - 3.4.5 | Medium |
AIKIDO-2026-10709 dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.3.0 - 3.4.1. | 3.3.0 - 3.4.1 | Medium |
AIKIDO-2026-10563 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.4.0 - 3.4.0. | 0.4.0 - 3.4.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant