Xmldom
This hub aggregates every CVE we track for Xmldom, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
2
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5MEDIUM2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
4
0
0
0
0
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Xmldom.
- CVE-2026-41675xmldom: XML node injection through unvalidated processing instruction serialization7.5
- CVE-2026-41674xmldom: XML injection through unvalidated DocumentType serialization7.5
- CVE-2026-41673xmldom: Denial of service via uncontrolled recursion in XML serialization7.5
- CVE-2026-41672xmldom: XML node injection through unvalidated comment serialization7.5
- CVE-2026-34601xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion7.5
- CVE-2022-39353xmldom allows multiple root nodes in a DOM9.4
- CVE-2022-37616A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "w...9.8
- CVE-2021-32796Misinterpretation of malicious XML input in xmldom6.5
- CVE-2021-21366Misinterpretation of malicious XML input4.3
Product normalization is registry-driven with AI assist and human review. How it works