LOWVulnerability
CVE-2026-75838
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.
Properties
- last_source
- NVD
- cve_id
- CVE-2026-75838
- signal_observed_at
- 2026-09-25T15:10:02+00:00
- retrieved_at
- 2026-09-25T15:10:02+00:00
- published_at
- 2026-08-18T12:19:34.050
- last_modified
- 2026-09-24T20:02:50.260
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph