CVE-2026-65901

DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.


We have discovered 63,650 live websites that are affected by CVE-2026-65901.

Run a Free Instant Scan




Affected Software

Product  DOMPurify
Category JavaScript Libraries
Vulnerable Domains63,650 live websites (100% of DOMPurify install base)
Vulnerable Versions
  • from 0 through 3.4.6
Vulnerable Versions Count67 versions ( 94% of all versions)



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Website Distribution by Country

Number of websites using CVE-2026-65901
United States17,531 websites



Germany8,640 websites
France3,898 websites
Japan2,889 websites
GB2,597 websites
Netherlands2,443 websites
Brazil2,181 websites
Italy1,993 websites
Poland1,841 websites
Switzerland1,558 websites

Website Distribution by TLD

Number of websites using CVE-2026-65901
.com24,250 websites
.de6,008 websites
.org2,873 websites
.nl2,193 websites
.com.br2,025 websites
.fr1,808 websites
.co.uk1,533 websites
.it1,453 websites
.net1,417 websites
.pl1,397 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65901

Top websites that are affected by CVE-2026-65901. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.com United States*,***
*****.*********.com United States*,***
********.org United States*,***
***********.ch Switzerland*,***
*****.com United States*,***
********.org United States*,***
***********.dk Denmark*,***
************.org France*,***
*********.com United States*,***
*************.com United States*,***
See full domain list

FAQ

A total of 63,650 websites have been identified as vulnerable to CVE-2026-65901, based on global website indexing conducted by WebTechSurvey.
The DOMPurify is affected by the CVE-2026-65901 vulnerability.
DOMPurify versions up to and including 3.4.6 are vulnerable to CVE-2026-65901.