Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-65914

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 18.8%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2026-65914


Contact Us

Shodan ® - All rights reserved