Zurück zur CVE-Übersicht
CVE-2026-75838
NONERisk Signal Score0/100 — NIEDRIG
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.3%
Exploit-Wahrscheinlichkeit (30 Tage)
Beschreibung
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.