{"schema_version":1,"title":"@xmldom/xmldom (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in @xmldom/xmldom (npm): 0 in the last 7 days and 15 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-83619, was published on 1 September 2026.","url":"https://junglewise.ai/threats/technologies/xmldom-xmldom","json_url":"https://junglewise.ai/threats/technologies/xmldom-xmldom.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/xmldom-xmldom","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":17,"all_time":22,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":15,"last_90_days":15,"last_365_days":19},"latest":[{"cve":"CVE-2026-83619","cvss":4,"epss":0.0052,"slug":"cve-2026-83619-xmldom-end-tag-whitespace-trim-redos","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the relea","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.657+00:00","url":"https://junglewise.ai/threats/cve-2026-83619-xmldom-end-tag-whitespace-trim-redos"},{"cve":"CVE-2026-83618","cvss":4,"epss":0.0057,"slug":"cve-2026-83618-xmldom-requirewellformed-doctype-validation-bypass-via-line","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requ","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.48+00:00","url":"https://junglewise.ai/threats/cve-2026-83618-xmldom-requirewellformed-doctype-validation-bypass-via-line"},{"cve":"CVE-2026-83617","cvss":4,"epss":0.0057,"slug":"cve-2026-83617-xmldom-xmlserializer-requirewellformed-bypass-via-line-terminator","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requ","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.273+00:00","url":"https://junglewise.ai/threats/cve-2026-83617-xmldom-xmlserializer-requirewellformed-bypass-via-line-terminator"},{"cve":"CVE-2026-83616","cvss":4,"epss":0.0061,"slug":"cve-2026-83616-xmldom-processing-instruction-target-injection-in-serialization","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.04+00:00","url":"https://junglewise.ai/threats/cve-2026-83616-xmldom-processing-instruction-target-injection-in-serialization"},{"cve":"CVE-2026-83615","cvss":4,"epss":0.0059,"slug":"cve-2026-83615-xmldom-quadratic-memory-consumption-in-namespace-parsing","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:39.887+00:00","url":"https://junglewise.ai/threats/cve-2026-83615-xmldom-quadratic-memory-consumption-in-namespace-parsing"},{"cve":"CVE-2026-83614","cvss":4,"epss":0.0059,"slug":"cve-2026-83614-xmldom-quadratic-time-parsing-denial-of-service","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:39.733+00:00","url":"https://junglewise.ai/threats/cve-2026-83614-xmldom-quadratic-time-parsing-denial-of-service"},{"cve":"CVE-2026-83613","cvss":4,"epss":0.006,"slug":"cve-2026-83613-xmldom-quadratic-time-attribute-deduplication","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:39.583+00:00","url":"https://junglewise.ai/threats/cve-2026-83613-xmldom-quadratic-time-attribute-deduplication"},{"cve":"CVE-2026-83612","cvss":4,"epss":0.0052,"slug":"cve-2026-83612-xmldom-html-raw-text-closing-tag-case-mismatch-causes-output","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HT","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:39.43+00:00","url":"https://junglewise.ai/threats/cve-2026-83612-xmldom-html-raw-text-closing-tag-case-mismatch-causes-output"},{"cve":"CVE-2026-83611","cvss":4,"epss":0.0062,"slug":"cve-2026-83611-xmldom-parser-silently-accepts-malformed-xml-end-tags","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"medium","exploited":false,"published_at":"2026-09-01T15:17:39.263+00:00","url":"https://junglewise.ai/threats/cve-2026-83611-xmldom-parser-silently-accepts-malformed-xml-end-tags"},{"cve":"CVE-2026-83610","cvss":4,"epss":0.0059,"slug":"cve-2026-83610-xmldom-xml-fragment-injection-in-entityreference-serialization","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"medium","exploited":false,"published_at":"2026-09-01T15:17:39.107+00:00","url":"https://junglewise.ai/threats/cve-2026-83610-xmldom-xml-fragment-injection-in-entityreference-serialization"},{"cve":"CVE-2026-83609","cvss":4,"epss":0.0054,"slug":"cve-2026-83609-xmldom-name-qname-validation-bypass-via-embedded-line-terminator","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the share","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-83609-xmldom-name-qname-validation-bypass-via-embedded-line-terminator"},{"cve":"CVE-2026-83608","cvss":4,"epss":0.0061,"slug":"cve-2026-83608-xmldom-doctype-name-injection-bypasses-requirewellformed","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.8+00:00","url":"https://junglewise.ai/threats/cve-2026-83608-xmldom-doctype-name-injection-bypasses-requirewellformed"},{"cve":"CVE-2026-83607","cvss":4,"epss":0.0061,"slug":"cve-2026-83607-xmldom-element-name-injection-via-createelement","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.65+00:00","url":"https://junglewise.ai/threats/cve-2026-83607-xmldom-element-name-injection-via-createelement"},{"cve":"CVE-2026-83606","cvss":4,"epss":0.0052,"slug":"cve-2026-83606-xmldom-pi-grammar-regex-redos-in-unterminated-processing","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, th","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.49+00:00","url":"https://junglewise.ai/threats/cve-2026-83606-xmldom-pi-grammar-regex-redos-in-unterminated-processing"},{"cve":"CVE-2026-83605","cvss":4,"epss":0.0061,"slug":"cve-2026-83605-xmldom-setattribute-attribute-name-injection","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.317+00:00","url":"https://junglewise.ai/threats/cve-2026-83605-xmldom-setattribute-attribute-name-injection"},{"cve":"CVE-2026-41675","cvss":7.5,"epss":0.0063,"slug":"cve-2026-41675-xmldom-xml-injection-in-xmlserializer-processing-instructions","title":"xmldom XML injection in XMLSerializer processing instructions","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:33.58+00:00","url":"https://junglewise.ai/threats/cve-2026-41675-xmldom-xml-injection-in-xmlserializer-processing-instructions"},{"cve":"CVE-2026-41673","cvss":7.5,"epss":0.0088,"slug":"cve-2026-41673-xmldom-uncontrolled-recursion-in-lib-dom-js","title":"xmldom uncontrolled recursion in lib/dom.js","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:33.257+00:00","url":"https://junglewise.ai/threats/cve-2026-41673-xmldom-uncontrolled-recursion-in-lib-dom-js"},{"cve":"CVE-2026-41672","cvss":7.5,"epss":0.0065,"slug":"cve-2026-41672-xmldom-xml-injection-in-xmlserializer-comment-serialization","title":"xmldom XML injection in XMLSerializer comment serialization","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:33.087+00:00","url":"https://junglewise.ai/threats/cve-2026-41672-xmldom-xml-injection-in-xmlserializer-comment-serialization"},{"cve":"CVE-2026-34601","cvss":7.5,"epss":0.0054,"slug":"cve-2026-34601-xmldom-xml-injection-via-unsafe-cdata-serialization","title":"xmldom XML injection via unsafe CDATA serialization","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:31.933+00:00","url":"https://junglewise.ai/threats/cve-2026-34601-xmldom-xml-injection-via-unsafe-cdata-serialization"},{"cve":"CVE-2022-39353","cvss":3.1,"epss":0.0127,"slug":"cve-2022-39353-xmldom-multiple-root-nodes-in-dom","title":"xmldom multiple root nodes in DOM","severity":"low","exploited":false,"published_at":"2022-11-01T17:29:11+00:00","url":"https://junglewise.ai/threats/cve-2022-39353-xmldom-multiple-root-nodes-in-dom"},{"cve":"CVE-2022-37616","cvss":3.1,"epss":0.017,"slug":"cve-2022-37616-xmldom-prototype-pollution-in-copy-function","title":"xmldom Prototype pollution in copy function","severity":"low","exploited":false,"published_at":"2022-10-11T20:42:57+00:00","url":"https://junglewise.ai/threats/cve-2022-37616-xmldom-prototype-pollution-in-copy-function"},{"cve":"CVE-2021-32796","cvss":3.1,"epss":0.0136,"slug":"cve-2021-32796-xmldom-improper-xml-character-escaping-in-element-serialization","title":"xmldom improper XML character escaping in element serialization","severity":"low","exploited":false,"published_at":"2021-08-03T16:57:05+00:00","url":"https://junglewise.ai/threats/cve-2021-32796-xmldom-improper-xml-character-escaping-in-element-serialization"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":15},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"}],"technology":{"hub":true,"name":"@xmldom/xmldom (npm)","slug":"xmldom-xmldom","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://www.npmjs.com/package/@xmldom/xmldom","repo_url":"https://github.com/xmldom/xmldom","description":"A pure JavaScript W3C standard-based DOMParser and XMLSerializer.","url":"https://junglewise.ai/threats/technologies/xmldom-xmldom"},"most_severe":[{"cve":"CVE-2026-41673","cvss":7.5,"epss":0.0088,"slug":"cve-2026-41673-xmldom-uncontrolled-recursion-in-lib-dom-js","title":"xmldom uncontrolled recursion in lib/dom.js","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:33.257+00:00","url":"https://junglewise.ai/threats/cve-2026-41673-xmldom-uncontrolled-recursion-in-lib-dom-js"},{"cve":"CVE-2026-41672","cvss":7.5,"epss":0.0065,"slug":"cve-2026-41672-xmldom-xml-injection-in-xmlserializer-comment-serialization","title":"xmldom XML injection in XMLSerializer comment serialization","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:33.087+00:00","url":"https://junglewise.ai/threats/cve-2026-41672-xmldom-xml-injection-in-xmlserializer-comment-serialization"},{"cve":"CVE-2026-41675","cvss":7.5,"epss":0.0063,"slug":"cve-2026-41675-xmldom-xml-injection-in-xmlserializer-processing-instructions","title":"xmldom XML injection in XMLSerializer processing instructions","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:33.58+00:00","url":"https://junglewise.ai/threats/cve-2026-41675-xmldom-xml-injection-in-xmlserializer-processing-instructions"},{"cve":"CVE-2026-34601","cvss":7.5,"epss":0.0054,"slug":"cve-2026-34601-xmldom-xml-injection-via-unsafe-cdata-serialization","title":"xmldom XML injection via unsafe CDATA serialization","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:31.933+00:00","url":"https://junglewise.ai/threats/cve-2026-34601-xmldom-xml-injection-via-unsafe-cdata-serialization"},{"cve":"CVE-2026-83616","cvss":4,"epss":0.0061,"slug":"cve-2026-83616-xmldom-processing-instruction-target-injection-in-serialization","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.04+00:00","url":"https://junglewise.ai/threats/cve-2026-83616-xmldom-processing-instruction-target-injection-in-serialization"},{"cve":"CVE-2026-83608","cvss":4,"epss":0.0061,"slug":"cve-2026-83608-xmldom-doctype-name-injection-bypasses-requirewellformed","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.8+00:00","url":"https://junglewise.ai/threats/cve-2026-83608-xmldom-doctype-name-injection-bypasses-requirewellformed"},{"cve":"CVE-2026-83607","cvss":4,"epss":0.0061,"slug":"cve-2026-83607-xmldom-element-name-injection-via-createelement","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.65+00:00","url":"https://junglewise.ai/threats/cve-2026-83607-xmldom-element-name-injection-via-createelement"},{"cve":"CVE-2026-83605","cvss":4,"epss":0.0061,"slug":"cve-2026-83605-xmldom-setattribute-attribute-name-injection","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:38.317+00:00","url":"https://junglewise.ai/threats/cve-2026-83605-xmldom-setattribute-attribute-name-injection"},{"cve":"CVE-2026-83613","cvss":4,"epss":0.006,"slug":"cve-2026-83613-xmldom-quadratic-time-attribute-deduplication","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:39.583+00:00","url":"https://junglewise.ai/threats/cve-2026-83613-xmldom-quadratic-time-attribute-deduplication"},{"cve":"CVE-2026-83615","cvss":4,"epss":0.0059,"slug":"cve-2026-83615-xmldom-quadratic-memory-consumption-in-namespace-parsing","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:39.887+00:00","url":"https://junglewise.ai/threats/cve-2026-83615-xmldom-quadratic-memory-consumption-in-namespace-parsing"}],"generated_at":"2026-09-26T10:14:00.201383+00:00"}