DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.
We have discovered 63,650 live websites that are affected by CVE-2026-49459.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 63,650 live websites (100% of DOMPurify install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 67 versions ( 94% of all versions) |
| 17,531 websites | |
| 8,640 websites | |
| 3,898 websites | |
| 2,889 websites | |
| 2,597 websites | |
| 2,443 websites | |
| 2,181 websites | |
| 1,993 websites | |
| 1,841 websites | |
| 1,558 websites |
| .com | 24,250 websites |
| .de | 6,008 websites |
| .org | 2,873 websites |
| .nl | 2,193 websites |
| .com.br | 2,025 websites |
| .fr | 1,808 websites |
| .co.uk | 1,533 websites |
| .it | 1,453 websites |
| .net | 1,417 websites |
| .pl | 1,397 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.*****.com | *,*** | ||
| *****.*********.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.ch | *,*** | ||
| *****.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.dk | *,*** | ||
| ************.org | *,*** | ||
| *********.com | *,*** | ||
| *************.com | *,*** |
FAQ