vciy

CVEs we hold for Cure53

Records whose assigning authority named Cure53 as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-75838DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hookcure53 DOMPurify
CVE-2026-66010DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLINGcure53 DOMPurify
CVE-2026-65914DOMPurify before 3.3.2 Mutation XSS via Re-Contextualizationcure53 DOMPurify
CVE-2026-65913DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILEScure53 DOMPurify
CVE-2026-65912DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTRcure53 DOMPurify
CVE-2026-65911DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakagecure53 DOMPurify
CVE-2026-65904DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE modecure53 DOMPurify
CVE-2026-65903DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGScure53 DOMPurify
CVE-2026-65902DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTagscure53 DOMPurify
CVE-2026-65901DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeNamecure53 DOMPurify
CVE-2026-65900DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOMcure53 DOMPurify
CVE-2026-65899DOMPurify before 3.4.9 Trusted Types Policy State Contaminationcure53 DOMPurify
CVE-2026-65898DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfigcure53 DOMPurify
CVE-2026-49978DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.contentcure53 DOMPurify
CVE-2026-49459DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOMcure53 DOMPurify
CVE-2026-49458DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checkscure53 DOMPurify
CVE-2026-47423DOMPurify XSS via `selectedcontent` re-clonecure53 DOMPurify
CVE-2026-41240DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)cure53 DOMPurify
CVE-2026-41239DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM modecure53 DOMPurify
CVE-2026-41238DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallbackcure53 DOMPurify
CVE-2026-0540DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XMLcure53 DOMPurify
CVE-2025-48050no title heldCure53 DOMPurify
CVE-2025-26791no title heldCure53 DOMPurify
CVE-2025-15599DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XMLcure53 DOMPurify
CVE-2024-48910DOMPurify vulnerable to tampering by prototype polutioncure53 DOMPurify
CVE-2024-47875DOMPurify nesting-based mXSScure53 DOMPurify
CVE-2024-45801Tampering by prototype polution in DOMPurifycure53 DOMPurify

27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.