Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

xmldom — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in xmldom, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the xmldom library, a JavaScript XML DOM implementation. The collection encompasses various weakness types, including denial of service, code injection, and improper input validation, covering reported issues from the library's initial release through recent updates. Readers can utilize this resource to track vendor advisories, understand specific weakness classes within XML parsing contexts, and review the complete vulnerability history of this product. The data is organized to facilitate analysis of recurring patterns, such as prototype pollution or entity expansion attacks, which have historically affected XML processing libraries. By examining the aggregated records, developers and security professionals can assess risk exposure for applications relying on xmldom and identify necessary mitigation strategies. The entries reflect a range of severity levels, from low-impact information disclosures to critical remote code execution flaws, providing a comprehensive view of the library's security posture over time. This aggregation serves as a reference point for understanding how vulnerabilities in XML parsing libraries evolve and are addressed by the maintainers.

Vendor: xmldom

CVE ID Title CVSS Severity Published
CVE-2026-83619 xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser CWE-400 8.7 High 2026-09-01
CVE-2026-83618 xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator CWE-91 8.7 High 2026-09-01
CVE-2026-83617 xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator CWE-91 8.7 High 2026-09-01
CVE-2026-83616 xmldom: Processing Instruction Target Injection Bypasses requireWellFormed CWE-91 8.7 High 2026-09-01
CVE-2026-83615 xmldom: Quadratic-memory consumption CWE-770 8.7 High 2026-09-01
CVE-2026-83614 xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge CWE-400 8.7 High 2026-09-01
CVE-2026-83613 xmldom: Quadratic-time attribute deduplication CWE-407 8.7 High 2026-09-01
CVE-2026-83612 xmldom: HTML raw-text closing-tag case mismatch causes output amplification CWE-178 8.7 High 2026-09-01
CVE-2026-83611 xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content CWE-1286 6.9 Medium 2026-09-01
CVE-2026-83610 xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization CWE-116 6.3 Medium 2026-09-01
CVE-2026-83609 xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path CWE-91 8.7 High 2026-09-01
CVE-2026-83608 xmldom: DocType `name` Injection Bypasses requireWellFormed CWE-91 8.7 High 2026-09-01
CVE-2026-83607 xmldom: Element name injection via createElement() bypasses requireWellFormed CWE-91 8.7 High 2026-09-01
CVE-2026-83606 xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions CWE-400 8.7 High 2026-09-01
CVE-2026-83605 xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed CWE-91 8.7 High 2026-09-01
CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization CWE-91 8.7 High 2026-05-07
CVE-2026-41674 xmldom: XML injection through unvalidated DocumentType serialization CWE-91 8.7 High 2026-05-07
CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization CWE-674 8.7 High 2026-05-07
CVE-2026-41672 xmldom: XML node injection through unvalidated comment serialization CWE-91 8.7 High 2026-05-07
CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion CWE-91 7.5 High 2026-04-02
CVE-2022-39353 xmldom allows multiple root nodes in a DOM CWE-20 9.4 Critical 2022-11-02
CVE-2021-32796 Misinterpretation of malicious XML input in xmldom CWE-116 6.5 Medium 2021-07-27
CVE-2021-21366 Misinterpretation of malicious XML input CWE-436 4.3 Medium 2021-03-12

All 23 known CVE vulnerabilities affecting xmldom with full Chinese analysis, references, and POCs where available.