3.4.16
12 years ago
13 days ago
Known vulnerabilities in the dompurify package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via insufficient sanitization in the HTML purification logic, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser by supplying malicious HTML input that bypasses DOMPurify's filtering. How to fix Cross-site Scripting (XSS)? Upgrade | <3.4.16 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <3.4.13 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions in the How to fix Improper Check for Unusual or Exceptional Conditions? Upgrade | <3.4.4 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | <3.4.0 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in the Note: This is only exploitable if the application enables How to fix Incomplete List of Disallowed Inputs? Upgrade | <3.4.12 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Improper Initialization in the How to fix Improper Initialization? Upgrade | <3.4.11 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Protection Mechanism Failure through the Note: This is only exploitable if a DOMPurify instance is reused across trust boundaries and a less-trusted integration or attacker has previously set an unsafe Trusted Types policy. How to fix Protection Mechanism Failure? Upgrade | <3.4.9 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Prototype Pollution in the Note: This is only exploitable if the sanitizer is used in How to fix Prototype Pollution? Upgrade | <3.4.6 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Trust Boundary Violation in the How to fix Trust Boundary Violation? Upgrade | <3.4.6 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Trust Boundary Violation through the mutation of Note: This is only exploitable if a hook is registered that mutates How to fix Trust Boundary Violation? Upgrade | <3.4.7 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <3.4.7 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <3.4.8 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Operator Precedence Logic Error in the form of short-circuit evaluation that gives precedence to How to fix Operator Precedence Logic Error? Upgrade | <3.4.0 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Permissive List of Allowed Inputs in the How to fix Permissive List of Allowed Inputs? Upgrade | <3.3.2 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Prototype Pollution in the How to fix Prototype Pollution? Upgrade | <3.3.2 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when sanitized HTML is reinserted into a new parsing context using How to fix Cross-site Scripting (XSS)? Upgrade | <3.3.2 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <3.2.7 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <2.5.9>=3.0.0 <3.3.2 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to incorrect handling of template literals in regular expressions. An attacker can manipulate the output of the script by injecting malicious payloads that bypass the How to fix Cross-site Scripting (XSS)? Upgrade | <3.2.4 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Prototype Pollution due to improper checks of the properties during the HTML sanitization process. How to fix Prototype Pollution? Upgrade | <2.4.2 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the improper sanitization of nested HTML elements in the How to fix Cross-site Scripting (XSS)? Upgrade | <2.5.0>=3.0.0 <3.1.3 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Prototype Pollution due to improper user input sanitization through the depth-checking mechanism, an attacker can exploit this vulnerability by using special nesting techniques to create a malicious HTML file. How to fix Prototype Pollution? Upgrade | <2.5.4>=3.0.0 <3.1.3 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Template Injection in How to fix Template Injection? Upgrade | <2.4.9>=3.0.0 <3.0.11 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Open Redirect in the How to fix Open Redirect? Upgrade | <1.0.11 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). This is due to a bypass of a previous XSS vulnerability. How to fix Cross-site Scripting (XSS)? Upgrade | <2.2.3 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when converting from SVG namespace. How to fix Cross-site Scripting (XSS)? Upgrade | <2.2.2 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). This occurs because a How to fix Cross-site Scripting (XSS)? Upgrade | <2.0.17 |
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari. How to fix Cross-site Scripting (XSS)? Upgrade | <2.0.3 |