Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Caverav

#48904of 54,968
5.3Total CVSS
Vulnerabilities · 1
PT-2026-63994
5.3
2026-03-27
Dompurify · Dompurify · CVE-2026-65914
**Name of the Vulnerable Software and Affected Versions** DOMPurify versions prior to 3.3.2 **Description** A mutation-XSS (Cross-Site Scripting) issue occurs when sanitized HTML is reinserted into special parsing contexts using `innerHTML` with wrappers such as `script`, `xmp`, `iframe`, `noembed`, `noframes`, or `noscript`. Attackers can use closing sequences to break out of the wrapper context during reparsing, which reactivates dangerous markup containing event handlers to execute arbitrary JavaScript. **Recommendations** Update to version 3.3.2 or later.