Vulnerabilidades en xmldom
23 resultadosAnálisis Vexday
A xmldom apresenta 8 vulnerabilidades em seu histórico, com 4 publicadas nos últimos 90 dias, indicando atividade recente de descobertas; nenhuma está sob ataque ativo documentado no momento. A fraqueza dominante (CWE-91 - XML Injection) e apenas 1 vulnerabilidade crítica (CVSS) sugerem um risco moderado, mas a cadência de novas descobertas recomenda monitoramento contínuo dos patches.
CVE-2021-32796MEDIUMMisinterpretation of malicious XML input in xmldomEPSS 1.4%CVE-2021-21366MEDIUMMisinterpretation of malicious XML inputEPSS 1.3%CVE-2022-39353CRITICALxmldom allows multiple root nodes in a DOMEPSS 1.3%CVE-2026-41673HIGHxmldom: Denial of service via uncontrolled recursion in XML serializationEPSS 0.9%CVE-2026-41672HIGHxmldom: XML node injection through unvalidated comment serializationEPSS 0.7%CVE-2026-41674HIGHxmldom: XML injection through unvalidated DocumentType serializationEPSS 0.7%CVE-2026-41675HIGHxmldom: XML node injection through unvalidated processing instruction serializationEPSS 0.6%CVE-2026-83611MEDIUMxmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing contentEPSS 0.6%CVE-2026-83616HIGHxmldom: Processing Instruction Target Injection Bypasses requireWellFormedEPSS 0.6%CVE-2026-83607HIGHxmldom: Element name injection via createElement() bypasses requireWellFormedEPSS 0.6%CVE-2026-83605HIGHxmldom: Attribute name injection via setAttribute() bypasses requireWellFormedEPSS 0.6%CVE-2026-83608HIGHxmldom: DocType `name` Injection Bypasses requireWellFormedEPSS 0.6%CVE-2026-83613HIGHxmldom: Quadratic-time attribute deduplicationEPSS 0.6%CVE-2026-83610MEDIUMxmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serializationEPSS 0.6%CVE-2026-83614HIGHxmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text mergeEPSS 0.6%CVE-2026-83615HIGHxmldom: Quadratic-memory consumptionEPSS 0.6%CVE-2026-83617HIGHxmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminatorEPSS 0.6%CVE-2026-83618HIGHxmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminatorEPSS 0.6%CVE-2026-83609HIGHxmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization pathEPSS 0.5%CVE-2026-34601HIGHxmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertionEPSS 0.5%