Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
WS-2024-0017
Published:May 15, 2026
Updated:May 15, 2026
Insufficient checks in DOMPurify allows an attacker to bypass sanitizers and execute arbitrary JavaScript code. This issue affects versions before 2.5.8 and 3.x before 3.2.3.
Affected Packages
dompurify (CDN_JS):
Affected version(s) >=0.7.0 <2.5.8
Fix Suggestion:
Update to version 2.5.8
dompurify (CDN_JS):
Affected version(s) >=3.0.0 <3.2.3
Fix Suggestion:
Update to version 3.2.3
auspice (CONDA):
Affected version(s) >=2.23.0 <=2.50.0
Fix Suggestion:
Update to version no_fix
dompurify (NPM):
Affected version(s) >=3.0.0 <3.2.3
Fix Suggestion:
Update to version 3.2.3
dompurify (NPM):
Affected version(s) >=0.4.0 <2.5.8
Fix Suggestion:
Update to version 2.5.8
datepickeroffsettime (NUGET):
Affected version(s) =1.0.3 <1.0.4
Fix Suggestion:
Update to version 1.0.4
nfdi4plants.fornax.template (NUGET):
Affected version(s) >=0.13.0 <=1.1.0
Fix Suggestion:
Update to version no_fix
markdown2pdf.console (NUGET):
Affected version(s) >=2.0.1 <=2.0.2
Fix Suggestion:
Update to version no_fix
jxlwqq/simditor (PHP):
Affected version(s) >=1.0.1 <=1.0.4
Fix Suggestion:
Update to version no_fix
nukeviet/nukeviet (PHP):
Affected version(s) >=dev-nukeviet4.6-future <dev-nukeviet5
Fix Suggestion:
Update to version dev-nukeviet5
freepik-labs/dom-purify (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/dompurify-2.3.2 <dev-dependabot/npm_and_yarn/dompurify-2.3.4
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/dompurify-2.3.4
centreon/centreon (PHP):
Affected version(s) =dev-MON-15375-fix-xss-security-vulnerabilities-in-ajaxldapsearch.js <dev-MON-15376-fix-xss-security-vulnerabilities-in-color_picker.php
Fix Suggestion:
Update to version dev-MON-15376-fix-xss-security-vulnerabilities-in-color_picker.php
nukeviet/nukeviet (PHP):
Affected version(s) =dev-nukeviet5.0-future
Fix Suggestion:
Update to version no_fix
freepik-labs/dom-purify (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/jsdom-18.0.0 <dev-dependabot/npm_and_yarn/jsdom-18.0.1
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/jsdom-18.0.1
nilsteampassnet/teampass (PHP):
Affected version(s) =dev-dependabot/github_actions/docker/login-action-3 <dev-teampass_3.0
Fix Suggestion:
Update to version dev-teampass_3.0
heycommunity/heycommunity-backend (PHP):
Affected version(s) >=v0.1.3 <dev-analysis-2221eB
Fix Suggestion:
Update to version dev-analysis-2221eB
hipdevteam/wpforms (PHP):
Affected version(s) >=1.6.0.2 <1.6.3
Fix Suggestion:
Update to version 1.6.3
depage/htmlform (PHP):
Affected version(s) >=dev-master <1.4.0
Fix Suggestion:
Update to version 1.4.0
tikiwiki/diagram (PHP):
Affected version(s) >=v24.2.0 <v24.4.0
Fix Suggestion:
Update to version v24.4.0
bravedave/dvc (PHP):
Affected version(s) >=v23.12.01 <=v24.01.01
Fix Suggestion:
Update to version no_fix
freepik-labs/dom-purify (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/jsdom-16.5.3 <dev-dependabot/npm_and_yarn/jsdom-16.7.0
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/jsdom-16.7.0
moonshine/moonshine (PHP):
Affected version(s) =dev-3.x-collapse-menu <3.0.1
Fix Suggestion:
Update to version 3.0.1
nilsteampassnet/teampass (PHP):
Affected version(s) >=dev-anti_bruteforce <dev-development
Fix Suggestion:
Update to version dev-development
phpffcms/ffcms-assets (PHP):
Affected version(s) >=1.3.2 <=1.3.3
Fix Suggestion:
Update to version no_fix
shiguangxiaotou3/myweb (PHP):
Affected version(s) =dev-master
Fix Suggestion:
Update to version no_fix
zaoub/zaoub (PHP):
Affected version(s) =dev-master <0.1
Fix Suggestion:
Update to version 0.1
levmyshkin/dom_purify (PHP):
Affected version(s) >=dev-main <=2.4.1
Fix Suggestion:
Update to version no_fix
adesso-mobile/php-confluence-client (PHP):
Affected version(s) =dev-master <0.1.0
Fix Suggestion:
Update to version 0.1.0
heycommunity/heycommunity-backend (PHP):
Affected version(s) >=dev-develop <dev-devs/composer-script
Fix Suggestion:
Update to version dev-devs/composer-script
freepik-labs/dom-purify (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/ws-7.4.6 <dev-dependabot/npm_and_yarn/ws-7.5.3
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/ws-7.5.3
moonshine/moonshine (PHP):
Affected version(s) >=2.14.0 <3.0.0-beta.2
Fix Suggestion:
Update to version 3.0.0-beta.2
freepik-labs/dom-purify (PHP):
Affected version(s) >=dev-master <0.2.4
Fix Suggestion:
Update to version 0.2.4
moonshine/moonshine (PHP):
Affected version(s) =dev-di-concept <dev-disable-outside-has-many
Fix Suggestion:
Update to version dev-disable-outside-has-many
moonshine/ui (PHP):
Affected version(s) >=3.0.0-alpha <3.0.0-beta.2
Fix Suggestion:
Update to version 3.0.0-beta.2
maxiao64/simditor (PHP):
Affected version(s) >=dev-master <=1.0.3
Fix Suggestion:
Update to version no_fix
ptadmin/admin (PHP):
Affected version(s) >=dev-main <v0.0.2
Fix Suggestion:
Update to version v0.0.2
freepik-labs/dom-purify (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/dompurify-2.3.5 <dev-dependabot/npm_and_yarn/dompurify-2.3.6
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/dompurify-2.3.6
zaoub/zaoub (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/dot-prop-4.2.1 <dev-dependabot/npm_and_yarn/lodash-4.17.19
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/lodash-4.17.19
freepik-labs/dom-purify (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/jsdom-20.0.3 <=dev-dependabot/npm_and_yarn/jsdom-21.1.1
Fix Suggestion:
Update to version no_fix
francoisjacquet/rosariosis (PHP):
Affected version(s) >=v9.0 <=v12.1.2
Fix Suggestion:
Update to version no_fix
freepik-labs/dom-purify (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/dompurify-2.3.8 <dev-dependabot/npm_and_yarn/dompurify-2.3.9
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/dompurify-2.3.9
hipdevteam/wpforms (PHP):
Affected version(s) >=1.8.9.1 <1.9.1.1
Fix Suggestion:
Update to version 1.9.1.1
freepik-labs/dom-purify (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/dompurify-2.4.1 <dev-dependabot/npm_and_yarn/lodash-4.17.21
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/lodash-4.17.21
jxlwqq/simditor (PHP):
Affected version(s) =dev-master <1.0.0
Fix Suggestion:
Update to version 1.0.0
freepik-labs/dom-purify (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/jsdom-19.0.0 <dev-dependabot/npm_and_yarn/jsdom-20.0.1
Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/jsdom-20.0.1
devsfort/fortblog (PHP):
Affected version(s) >=dev-dev <=1.0.1
Fix Suggestion:
Update to version no_fix
heycommunity/heycommunity-backend (PHP):
Affected version(s) =dev-feature/dashboard <dev-fix/get-status-code
Fix Suggestion:
Update to version dev-fix/get-status-code
calven/simditor (PHP):
Affected version(s) >=dev-master <=v0.0.2
Fix Suggestion:
Update to version no_fix
anna-stupina38/cinema-project (PHP):
Affected version(s) >=dev-master <=1.3
Fix Suggestion:
Update to version no_fix
zaoub/zaoub (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/serialize-javascript-5.0.1 <=dev-dependabot/npm_and_yarn/yargs-parser-20.2.4
Fix Suggestion:
Update to version no_fix
heycommunity/heycommunity-backend (PHP):
Affected version(s) =dev-main <dev-migration
Fix Suggestion:
Update to version dev-migration
Do you need more information?
Contact Us
CVSS v4
Base Score:
5.1
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.1
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE