Количество 4
Количество 4
CVE-2026-65913
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.
CVE-2026-65913
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.
CVE-2026-65913
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in ...
GHSA-cj63-jhhr-wcxv
DOMPurify USE_PROFILES prototype pollution allows event handlers
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65913 DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered. | CVSS3: 6.1 | 0% Низкий | 12 дней назад | |
CVE-2026-65913 DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered. | CVSS3: 6.1 | 0% Низкий | 12 дней назад | |
CVE-2026-65913 DOMPurify before 3.3.2 contains a prototype pollution vulnerability in ... | CVSS3: 6.1 | 0% Низкий | 12 дней назад | |
GHSA-cj63-jhhr-wcxv DOMPurify USE_PROFILES prototype pollution allows event handlers | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу