FeatureFuel
1

Update DOMPurify

Source: elementor/elementor#37355 · opened by @brownemint
Describe the Problem My customer uses AppCheck to scan their website on a monthly basis. This month, it flagged 30 CVE's related to the version of DOMPurify that the Elementor plugin is using (DOMPurify 3.3.0). 1. Cure53 Dompurify v3.3.0 - Out of Date Software Version Detected 2. Cure53 DOMPurify 3.x < v3.4.9 - Failure or Bypass of Security Protection Mechanism (CVE-2026-65899) 3. Cure53 DOMPurify < v3.4.0 - Cross-Site Scripting ('XSS') Vulnerability (CVE-2026-65911) 4. Cure53 DOMPurify <= v3.4.6 - Cross-Site Scripting ('XSS') Vulnerability (CVE-2026-65901) 5. Cure53 DOMPurify < v3.4.11 - Stored (Persistent) Cross-Site Scripting ('XSS') Vulnerability (CVE-2026-65898) 6. Cure53 DOMPurify < v3.4.0 - Improper Enforcement of Behavioral Workflow (CVE-2026-65903) 7. Cure53 DOMPurify < v3.4.7 - Trust Boundary Violation Vulnerability (CVE-2026-65902) 8. Cure53 DOMPurify < v3.3.2 - Cross-Site Scripting ('XSS') Vuln…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests