Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-48910


DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.


Published

2024-10-31T15:15:15.720

Last Modified

2025-09-23T02:01:59.903

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-1321

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cure53 dompurify < 2.4.2 Yes

References