CVE-2026-75838EPSS p20.8%
CVE-2026-75838CVE-2026-75838
Description
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.
Scoring
| EPSS | 0.30% probability of exploitation · percentile 20.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-24 |