A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
72%
Total Score
11
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-34601 xmldom is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 0.6.0. | 0.0.0 - 0.6.0 | High |
CVE-2022-39353 xmldom is vulnerable to Improper Input Validation in versions 0.0.0 - 0.6.0. | 0.0.0 - 0.6.0 | Critical |
CVE-2022-37616 xmldom is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 0.6.0. | 0.0.0 - 0.6.0 | Critical |
CVE-2021-32796 xmldom is vulnerable to Improper Encoding or Escaping of Output in versions 0.0.0 - 0.6.0. | 0.0.0 - 0.6.0 | Medium |
CVE-2021-21366 xmldom is vulnerable to Misinterpretation of Input in versions 0.0.0 - 0.5.0. | 0.0.0 - 0.5.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant