VDB

CVE-2026-65914

CVE-2026-65914 PUBLISHED CVSS 5.3 MEDIUM

Reported by VulnCheck · Published July 23, 2026

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.

Risk Scores

CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products

VendorProductVersions
cure53DOMPurify0, 3.3.2
cure53DOMPurify0, 3.3.2
chainguardwazuh-dashboard0, 0, 0
cure53dompurify0

Timeline

  • Mar 27, 2026 CVE Published
  • Jul 23, 2026 Coalition ESS Score
  • Jul 25, 2026 EPSS Score
  • Jul 26, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›