Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4245 | DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS). |
Github GHSA |
GHSA-vhxf-7vqr-mrjg | DOMPurify allows Cross-site Scripting (XSS) |
Tue, 07 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cure53
Cure53 dompurify |
|
| CPEs | cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cure53
Cure53 dompurify |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 01 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat network Observ Optr
|
|
| CPEs | cpe:/a:redhat:network_observ_optr:1.9::el9 | |
| Vendors & Products |
Redhat network Observ Optr
|
Thu, 15 May 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhdh
|
|
| CPEs | cpe:/a:redhat:rhdh:1.6::el9 | |
| Vendors & Products |
Redhat rhdh
|
Wed, 16 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift_ai:2.19::el8 |
Fri, 28 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Ai
|
|
| CPEs | cpe:/a:redhat:openshift_ai:2.16::el8 | |
| Vendors & Products |
Redhat openshift Ai
|
Wed, 12 Mar 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat ansible Automation Platform
|
|
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.5::el8 cpe:/a:redhat:ansible_automation_platform:2.5::el9 |
|
| Vendors & Products |
Redhat ansible Automation Platform
|
Thu, 27 Feb 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat service Mesh |
|
| CPEs | cpe:/a:redhat:service_mesh:2.5::el8 | |
| Vendors & Products |
Redhat
Redhat service Mesh |
Tue, 18 Feb 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Feb 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS). | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-14T15:30:49.790Z
Reserved: 2025-02-14T00:00:00.000Z
Link: CVE-2025-26791
Updated: 2025-02-14T15:30:43.141Z
Status : Analyzed
Published: 2025-02-14T09:15:08.067
Modified: 2025-10-07T20:56:12.317
Link: CVE-2025-26791
OpenCVE Enrichment
No data.
EUVD
Github GHSA