Total vulnerabilities in the database
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Software | From | Fixed in |
---|---|---|
cure53 / dompurify | - | 2.0.17 |
debian / debian_linux | 9.0 | 9.0.x |
microsoft / visual_studio_2017 | 15.9 | 15.9.x |
microsoft / visual_studio_2019 | 16.0 | 16.0.x |
microsoft / visual_studio_2019 | 16.4 | 16.4.x |
microsoft / visual_studio_2019 | 16.8 | 16.8.x |
microsoft / visual_studio_2019 | 16.7 | 16.7.x |
oracle / application_express | - | 21.1.0.00.01 |
![]() |
- | 2.0.17 |