DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It's written in JavaScript and works in all modern browsers (Safari, Opera (15+), Internet Explorer (10+), Firefox and Chrome - as well as almost anything else usin
85%
Total Score
100
100
100
75
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10709 New dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.3.0 - 3.4.1. | 3.3.0 - 3.4.1 | Medium |
AIKIDO-2026-10563 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.4.0 - 3.4.0. | 0.4.0 - 3.4.0 | Medium |
CVE-2026-41240 dompurify is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.0. | 0.0.0 - 3.4.0 | Medium |
CVE-2026-41239 dompurify is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.10 - 3.4.0. | 1.0.10 - 3.4.0 | Medium |
CVE-2026-41238 dompurify is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.1 - 3.4.0. | 3.0.1 - 3.4.0 | Medium |
No direct dependencies.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant