Vulnerabilities
CVE-2026-0540 - DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML
CVE ID : CVE-2026-0540 Published : March 3, 2026, 5:26 p.m. | 49 minutes ago Description : DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...