CVE-2026-65904

DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to stringify the element (yielding '[object HTMLDivElement]'), silently reset IN_PLACE to false, and return the unsanitized element unchanged with any XSS payloads intact.


We have discovered 63,648 live websites that are affected by CVE-2026-65904.

Run a Free Instant Scan




Affected Software

Product  DOMPurify
Category JavaScript Libraries
Vulnerable Domains63,648 live websites (100% of DOMPurify install base)
Vulnerable Versions
  • from 0 through 3.4.4
Vulnerable Versions Count66 versions ( 93% of all versions)



Details

  • Published - Jul 23, 2026
  • Updated - Jul 24, 2026

Credits

  • fg0x0 (reporter)

Website Distribution by Country

Number of websites using CVE-2026-65904
United States17,529 websites



Germany8,640 websites
France3,898 websites
Japan2,889 websites
GB2,597 websites
Netherlands2,443 websites
Brazil2,181 websites
Italy1,993 websites
Poland1,841 websites
Switzerland1,558 websites

Website Distribution by TLD

Number of websites using CVE-2026-65904
.com24,248 websites
.de6,008 websites
.org2,873 websites
.nl2,193 websites
.com.br2,025 websites
.fr1,808 websites
.co.uk1,533 websites
.it1,453 websites
.net1,417 websites
.pl1,397 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65904

Top websites that are affected by CVE-2026-65904. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.com United States*,***
*****.*********.com United States*,***
********.org United States*,***
***********.ch Switzerland*,***
*****.com United States*,***
********.org United States*,***
***********.dk Denmark*,***
************.org France*,***
*********.com United States*,***
*************.com United States*,***
See full domain list

FAQ

A total of 63,648 websites have been identified as vulnerable to CVE-2026-65904, based on global website indexing conducted by WebTechSurvey.
The DOMPurify is affected by the CVE-2026-65904 vulnerability.
DOMPurify versions up to 3.4.4 are vulnerable to CVE-2026-65904.
CVE-2026-65904 is resolved in version 3.4.4 of DOMPurify.