@xmldom/xmldom
This hub aggregates every CVE we track for @xmldom/xmldom, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
2
Critical
0
High
0
In CISA KEV
Severity distribution
CRITICAL2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 3 most recently published vulnerabilities affecting @xmldom/xmldom.
- CVE-2022-39353xmldom allows multiple root nodes in a DOM9.4
- CVE-2022-37616A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "w...9.8
- CVE-2021-32796Misinterpretation of malicious XML input in xmldom6.5
Product normalization is registry-driven with AI assist and human review. How it works