Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

xmldom — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting xmldom. AI-powered Chinese analysis, POCs, and references for each vulnerability.

XMLDOM is a JavaScript library for parsing and manipulating XML documents, commonly used in web applications for data processing and document handling. Historically, it has been susceptible to multiple security vulnerabilities, including remote code execution (RCE) and cross-site scripting (XSS) attacks, often stemming from improper input validation and insecure parsing of XML data. The library's eight recorded CVEs highlight risks related to entity expansion attacks and malicious payload processing. While no major public incidents have been widely documented, the consistent pattern of vulnerabilities in XML processing libraries underscores the importance of implementing proper input sanitization and considering alternative, more secure XML handling approaches in web development.

Top products by xmldom: xmldom
CVE ID Title CVSS Severity Published
CVE-2026-83619 xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser — xmldom CWE-400 8.7 High 2026-09-01
CVE-2026-83618 xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-83617 xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-83616 xmldom: Processing Instruction Target Injection Bypasses requireWellFormed — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-83615 xmldom: Quadratic-memory consumption — xmldom CWE-770 8.7 High 2026-09-01
CVE-2026-83614 xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge — xmldom CWE-400 8.7 High 2026-09-01
CVE-2026-83613 xmldom: Quadratic-time attribute deduplication — xmldom CWE-407 8.7 High 2026-09-01
CVE-2026-83612 xmldom: HTML raw-text closing-tag case mismatch causes output amplification — xmldom CWE-178 8.7 High 2026-09-01
CVE-2026-83611 xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content — xmldom CWE-1286 6.9 Medium 2026-09-01
CVE-2026-83610 xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization — xmldom CWE-116 6.3 Medium 2026-09-01
CVE-2026-83609 xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-83608 xmldom: DocType `name` Injection Bypasses requireWellFormed — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-83607 xmldom: Element name injection via createElement() bypasses requireWellFormed — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-83606 xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions — xmldom CWE-400 8.7 High 2026-09-01
CVE-2026-83605 xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed — xmldom CWE-91 8.7 High 2026-09-01
CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization — xmldom CWE-91 8.7 High 2026-05-07
CVE-2026-41674 xmldom: XML injection through unvalidated DocumentType serialization — xmldom CWE-91 8.7 High 2026-05-07
CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization — xmldom CWE-674 8.7 High 2026-05-07
CVE-2026-41672 xmldom: XML node injection through unvalidated comment serialization — xmldom CWE-91 8.7 High 2026-05-07
CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion — xmldom CWE-91 7.5 High 2026-04-02
CVE-2022-39353 xmldom allows multiple root nodes in a DOM — xmldom CWE-20 9.4 Critical 2022-11-02
CVE-2021-32796 Misinterpretation of malicious XML input in xmldom — xmldom CWE-116 6.5 Medium 2021-07-27
CVE-2021-21366 Misinterpretation of malicious XML input — xmldom CWE-436 4.3 Medium 2021-03-12

This page lists every published CVE security advisory associated with xmldom. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.