CVE-2025-26791
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site sc
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
MEDIUM · CVSS 4.5
EPSS 0.00108
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0