CVE-2026-49459

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

List of 63,529 websites affected by CVE-2026-49459
Contact us to get more info

DomainCountryRankContacts
*******.*****.com United States*,***
*****.*********.com United States*,***
********.org United States*,***
***********.ch Switzerland*,***
*****.com United States*,***
********.org United States*,***
***********.dk Denmark*,***
************.org France*,***
*********.com United States*,***
*************.com United States*,***
*****************.org United States**,***
***.ru Russia**,***
******.********.edu United States**,***
********.no Norway**,***
*****************.***.uk GB**,***
************.org United States**,***
**.gov United States**,***
**.se Sweden**,***
****.com GB**,***
*********.be Belgium**,***