Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-75838

9 дней назад

(DOMPurify before 3.4.13 contains a cross-site scripting vulnerability ...)

EPSS: Низкий
nvd логотип

CVE-2026-75838

10 дней назад

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.

EPSS: Низкий
debian логотип

CVE-2026-75838

10 дней назад

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability ...

EPSS: Низкий
github логотип

GHSA-748c-f84h-hp2v

10 дней назад

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-75838

(DOMPurify before 3.4.13 contains a cross-site scripting vulnerability ...)

0%
Низкий
9 дней назад
nvd логотип
CVE-2026-75838

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.

0%
Низкий
10 дней назад
debian логотип
CVE-2026-75838

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability ...

0%
Низкий
10 дней назад
github логотип
GHSA-748c-f84h-hp2v

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.

0%
Низкий
10 дней назад

Уязвимостей на страницу